Site Monitor
Site Monitor watches your company websites so your team can catch problems before customers do. Use it to monitor your public website, booking page, customer portal, online store, or any other site your business depends on.
Open Site Monitor from the main navigation after the plugin is enabled in Settings → Features.
What Site Monitor checks
For each monitored site, ToolbagCRM can watch for:
- Downtime — whether the site can be reached and returns a healthy HTTP response.
- SSL certificate issues — whether the browser padlock certificate is expired or getting close to expiration.
- DNS changes — whether the site's DNS records change unexpectedly.
- Content changes — whether important visible page text changes from the previous check.
- Signs of compromise — suspicious changes or findings that may need review.
Site Monitor is not tied to customer records. It is meant for the websites your own business relies on, such as your main marketing site or a separate booking domain.
When to use this
- Your business depends on a public website, booking page, customer portal, or online store and you need to know when it goes down before customers report it.
- You want early warnings when an SSL certificate is about to expire so your booking or payment pages do not start showing browser security errors.
- You want to catch unexpected DNS changes or page defacement that could point customers to the wrong place or expose them to compromise.
- You need alert emails sent to the right people automatically instead of relying on someone to manually check the site.
Before you start
- Communications must be enabled in Settings → Features so Site Monitor can send alert emails to the recipients you configure.
- Site Monitor is a premium plugin. Enable it in Settings → Features under the Plugins section.
- Have the public URLs for every website your business relies on ready — your main site, booking page, customer portal, online store, and any other domain customers use to reach you.
- Decide who should receive alert emails (owner, office manager, web maintainer) before adding sites so you can set up notification recipients during or right after setup.
Add a site
- Open Site Monitor.
- Select Add site.
- Enter the public URL you want ToolbagCRM to watch. ToolbagCRM adds
https://when the scheme is omitted, rejects private/non-web addresses, and treats duplicate URLs as the same site when only the scheme, capitalization, trailing slash, or leadingwww.differs. - Add a label your team will recognize, such as
Main websiteorBooking page. If you leave the label blank, ToolbagCRM uses the site's domain. - Choose whether to turn on Monitor TLS certificate, Monitor DNS, Monitor content, and Notify me when this page changes. For noisy pages, add CSS selectors under Ignore sections so rotating areas are skipped.
- Select Add.
After the site is added, it appears as a card on the Site Monitor page with its current health, last known status, and any open alerts. ToolbagCRM starts the first check right away in the background, so the card may move from Unknown to Healthy, Warning, or Down shortly after creation.
Accounts can add sites up to their current Site Monitor limit. If you reach the limit, choose which existing site to remove or ask about expanding your allowance before adding another one.
Read the dashboard
The summary cards at the top of Site Monitor show:
- Healthy — sites with no current problems.
- Warnings — sites that need attention, such as a certificate nearing expiration.
- Down — sites that appear unreachable or unhealthy.
- Open alerts — unresolved alerts across all monitored sites.
Use the filter tabs to focus on all sites, healthy sites, warnings, or down sites.
Review a site
Open a site card to see more detail, including:
- recent check history,
- open alerts,
- the current HTTP status,
- SSL and DNS check results,
- content-change details when a page changed, and
- available deep-scan results.
Use Check now when you want ToolbagCRM to re-check a site immediately instead of waiting for the normal schedule.
Handle alerts
Site Monitor raises alerts when a check finds something that may require follow-up. Examples include an expiring certificate, a site that appears down, DNS changes, or a page content change.
For each alert:
- Open the affected site.
- Review the alert message and recent check history. DNS-change alerts show the records that were removed and added so your web maintainer can compare them against the intended DNS change.
- If the alert is about a content change, use View changes to compare the before-and-after page text.
- Fix or investigate the issue outside ToolbagCRM as needed.
- Mark the alert resolved when your team has handled it.
Resolving an alert clears it from the open-alert list. It does not delete the check history.
Settings
Select Settings on the Site Monitor page. On the Site Monitor setup page, administrators can configure:
- how often sites should be checked,
- how many days before SSL expiration should count as a warning,
- which email recipients should receive site alerts, and
- the monthly budget for AI-assisted compromise checks.
Add one email address per line in the recipients box so the right people hear about problems quickly.
Deep monitoring
Site Monitor includes a deeper scan area for looking beyond a single page. Deep scans can show discovered subdomains, pages, endpoints, and findings such as vulnerable components or missing security headers.
Select Run deep scan from the site detail view when a scan is available. While its status is Queued or Running, select Refresh scan status to load the current status and results instead of waiting for the page to update on its own.
Deep scans are limited unless the Deep monitoring add-on is enabled. The setup page shows whether your account is using the free scan allowance or daily deep scans through the add-on.
For ownership and safety, ToolbagCRM may require a verification step before deep-scanning a site. This helps confirm that your business controls the domain being scanned.
Tips
- Monitor every public place customers use to reach you: your main site, booking page, online store, and customer portal.
- Add alert recipients for both an owner/manager and whoever maintains your website.
- Keep content-change alerts on for important pages such as booking, contact, and financing pages.
- Turn off Notify me when this page changes or add CSS selectors under Ignore sections for pages that change constantly, such as blogs or rotating testimonials.
- Use Check now after adding or editing a site when you need a fresh result immediately; otherwise the first background check will update the card shortly after creation.
- If you change a monitored site's URL, ToolbagCRM resets the old DNS, SSL, and content baselines so the next check establishes a clean comparison for the new address.
- Review warnings before busy seasons so an expired certificate does not block customers from booking work.
Troubleshooting
Alerts are not being sent
Site Monitor depends on the Communications plugin to send alert emails. Confirm Communications is enabled. Select Settings on the Site Monitor page, then confirm email addresses are listed under Recipients.
Site Monitor settings do not load or save
If the setup page says it could not load Site Monitor settings, select Retry. The form stays hidden until the current settings load. If saving fails, check your connection and select Save changes again; your entries remain in the form so you can retry without re-entering them.
Adding a site fails with a URL error
Site Monitor only accepts public http or https URLs. Private addresses (localhost, 127.0.0.1, 192.168.x.x, 10.x.x.x) and non-web schemes (ftp, ssh) are rejected because the monitor needs to reach the site from ToolbagCRM's servers. Check for typos and use a public hostname such as example.com or a full URL such as https://example.com; ToolbagCRM adds https:// when the scheme is omitted.
Adding a site says the URL is already being monitored
ToolbagCRM blocks duplicate monitored sites so your team does not receive two alerts for the same public URL. It treats https://example.com, http://www.example.com/, and capitalization-only changes as the same site; use the existing site card instead, or add a genuinely different subdomain such as support.example.com.
Adding a site says the monitored-site limit was reached
Your account has a Site Monitor site limit. Remove a site you no longer need to watch, or ask about increasing the allowance before adding another website.
Deep scans are not running
Deep scans require domain ownership verification. After adding a site, ToolbagCRM generates a verification token. Publish it as a DNS TXT record (tbcrm-verify=<token>) on the domain, then return to the site detail page to confirm verification. Until ownership is verified, deep scans are blocked for safety.
Content-change alerts fire too often
Pages with rotating testimonials, blog feeds, or live chat widgets change on every load and can trigger constant alerts. Open the site settings and either turn off Notify me when this page changes, or add CSS selectors under Ignore sections for the regions that change frequently (for example, .testimonial-carousel or #live-chat). The rest of the page will still be monitored for unexpected changes.
SSL warning says "unknown"
SSL checks require the site to return a valid TLS certificate over HTTPS. If the site uses HTTP only, uses a self-signed certificate, or is behind a firewall that blocks ToolbagCRM's probe, the SSL status will show unknown. Confirm the site is publicly reachable over HTTPS before enabling SSL checks.
Site shows as Down but loads in a browser
Site Monitor probes from ToolbagCRM's servers, not from your local network. If the site is behind a firewall, VPN, or IP allow-list that does not include ToolbagCRM's infrastructure, the probe will fail even though the site works for you. Whitelist ToolbagCRM's probe IPs or confirm the site is publicly accessible.
Check now shows a countdown instead of running immediately
The Check now button has a short cooldown to prevent rapid repeated probes. If you just ran a check, the button shows a countdown (for example, Check now (25s)) until the cooldown expires. Wait for the countdown to finish, then click again.
