sitereliability.sh

tls · dns · headers · uptime

Your certs are fine.
Until they quietly aren't.

Certificates, DNS, and security headers now break more often than your code does. Grade any host from the terminal in ten seconds — no signup, no agent, just readable POSIX shell.

Piping strangers' shell into sh is a leap of faith — so don't. Every script is short, read-only, and sha256-published.

$ curl -fsSL sitereliability.sh/tls.sh | sh -s -- yourdomain.com
sitereliability.sh/tls.sh — report card for yourdomain.com:443
pass TLS handshake completed
pass certificate chain verifies against system trust store
pass negotiated TLSv1.3
warn certificate expires within 30 days (Sep 6 2026)
pass HSTS header present
warn no X-Content-Type-Options: nosniff
4 pass, 2 warn, 0 fail
verdict: decent, could be tighter
Renewal is about to get 4x more frequent.
Expiry watching: https://sitereliability.sh

why now

The 47-day certificate era is scheduled.

The CA/Browser Forum has voted TLS certificate lifetimes down, industry-wide. Every renewal is a chance to silently fail — and there are about to be a lot more renewals.

  1. March 2026 — shipped 200 days

    Maximum certificate lifetime, already in force.

  2. March 2027 100 days

    Four renewals a year, per certificate.

  3. March 2029 47 days

    Renewal becomes routine. Routine fails quietly.

Automation renews certificates. Nothing checks the automation. That's the job.

free, forever

Terminal tools

Each one prints a pass/warn/fail report card and exits non-zero on failure, so they drop straight into CI or cron. Read-only, no sudo, no telemetry.

tls.sh

TLS & certificate report card for any hostname: chain trust, protocol floor, legacy protocol acceptance, expiry buckets, security headers.

curl -fsSL https://sitereliability.sh/tls.sh | sh -s -- example.com
view sourcePOSIX sh · read-only

health.sh

One-screen health snapshot of the box you run it on: load, memory, disk and inode pressure, failed units, pending reboots, clock sync, listening ports.

curl -fsSL https://sitereliability.sh/health.sh | sh
view sourcePOSIX sh · read-only

audit.sh

Basic hardening audit: sshd posture, firewall state, unattended upgrades, PATH and account hygiene. Reports what it can't verify without root instead of guessing.

curl -fsSL https://sitereliability.sh/audit.sh | sh
view sourcePOSIX sh · read-only

the suite

Same checks, bigger picture.

Report Card scanner coming soon

TLS chain and expiry, security headers, DNS (CAA, DNSSEC, SPF/DMARC), redirect hygiene, response time — from the browser, with a letter grade, prioritized fixes, and copy-pasteable config for nginx, Apache, Caddy, and lighttpd.

free · shareable results · embeddable grade badge

Cert & Domain Watchdog coming soon

Uptime monitors tell you when you're down. We tell you thirty days before: certificate expiry and chain changes, domain expiry, and renewal automation that quietly stopped working.

from $9/month · email, Slack & webhook alerts

trust, but verify

Never pipe blind.

Every tool is served as plain text so you can read it in the browser first. Sums are published at /checksums.txt, scripts are POSIX sh with no sudo and no network calls beyond the check itself, and probes identify themselves with an honest User-Agent.