certscore.org · 29 surface checks shown, plus 35 application services watched as one group · two readings on 24 Aug 2026, 8:45 PM and 10:14 PM
These readings were taken by hand on 24 August 2026, at the two times named above, and have not changed since: this page is a preview built from real measurements, not a live feed. StatusPost itself is already watched minute by minute at status.statuspost.org; these member pages join that runner next. Nothing here is a guess, but nothing here is fresher than its timestamp.
100%answered when checked
12 of 12 probes across two readings, every city, both times. A small denominator,
said out loud: once watching begins this becomes 1,440 checks a day.
Website100%all good
Name lookup100%all good
Email setup100%all good
Domain & certificate100%cert 69d · domain 147d
all goodneeded a humanbefore watching began
First answer, from six cities, latest reading, 10:14 PM
Los Angeles, US0.51s
São Paulo, BR0.47s
Helsinki, FI0.35s
Tokyo, JP0.60s
Sydney, AU0.59s
Lagos, NG0.27s
Metrics and trends
Each number from the first reading beside the latest one. Once watching runs
daily, these grow into week and month views.
Metric8:45 PM10:14 PMTrend
Fastest city, first answer0.17s0.27ssteady
Slowest city, first answer2.47s0.60simproved
Email records in place3 of 44 of 4improved
Browser protections on1 of 66 of 6improved
Certificate runway69 days69 dayscounts down daily
Domain runway147 days147 dayscounts down daily
Everything watched
All of it from one address. Nothing was installed on the site and no password
was handed over.
Plain httppolitely forwarded to the secure addressall good
www variantanswers alongside the bare domainall good
Reachability
Name lookupthe address resolves cleanlyall good
Second opinionan independent resolver agreesall good
Modern networksreachable over IPv6all good
Email
Sender record (SPF)says who may send as this domainpresent
Signing keys (DKIM)mail is signedpresent
Forgery policy (DMARC)monitoring mode, added between the two readingspresent
Mail routing (MX)incoming mail has somewhere to gopresent
Browser protections, all six by name
Insist on the padlockthe browser remembers to only ever use the secure connection (HSTS)on
Refuse to be framedno other site can wrap this one in an invisible frame to steal clickson
No file-type guessingthe browser takes files at their word instead of guessing (nosniff)on
Content rulesthe page declares what it is allowed to load, and the browser enforces it (CSP)on
Referrer courtesywhen someone follows a link away, only the site name travels with them, not the full page address (Referrer-Policy)on
Feature permissionsthe site declares it will never ask the browser for the camera, microphone, or location (Permissions-Policy)on
APIs and machine endpoints
Application services35 edge functions behind the app (sign-in, credential verification, AI moderation, the cron jobs), each held to the exact answer it gave when watching began. Most reply with a protective 401 or 403 to anyone without the right key; a plain 200 where a 401 is expected is itself the alarm. Named on the private operator view, not here, so this page is never a map for an attacker.35 watched100%
Data & auth APIsthe sign-in, database and storage services every app build talks to, watched through auth.certscore.orgall good100%
robots.txtthe file that tells search engines the rules200, plain text100%
Store handoffthe link that sends a phone to the right app store302, as designed100%
Sign-in serviceits healthy answer to strangers is a 404, learned by measurement and held to404, as expected
Trust signals, optional but worth knowing
Note for researchersa standard file telling security researchers who to contact (security.txt)not set up, optional
Certificate rules (CAA)a record naming which authorities may issue certificates for this domainnot set up, optional
Signed name lookups (DNSSEC)cryptographic proof that DNS answers were not tampered withnot set up, optional
Domain and certificate
Certificaterenews by 1 November 202669 days away
Domain registrationpaid through 18 January 2027147 days away
Reading log
What each reading found, and what changed in between. On the live product this
becomes the incident history.
First reading, 8:45 PMBaseline set. Three findings: no DMARC email record, one of six browser protections on, and South America waiting 2.47 seconds for a first answer.
Between readingsThe DMARC record was added, all six browser protections were switched on, and the get-the-app link was repaired end to end.
Second reading, 10:14 PMEmail records four of four. Protections six of six. South America answered in 0.47 seconds; the slow first read was a cold cache serving its first visitor.
26 AugA review of our own pages found three displays wrong on this page: the week axis carried weekday names shifted by one day, the history strips lit hours and days no reading ever touched, and this page's feed counted four browser protections where the page itself says six. All corrected. The readings themselves, and every number built from them, were never wrong; what misled was how much history the pictures claimed. Corrections like this are logged here because that is the deal.
Follow these updates:RSS feed·add it to Slack:/feed subscribe https://status.certscore.org/feed.xml
Everything found by the first reading was closed before the second one ran. That ninety-minute loop, find it, fix it, prove it, is the product.