Skip to main content

The CompleteStatus Blog

Monitoring & security, explained

Practical, no-fluff guides on uptime and security monitoring — fixing security headers, email authentication, SSL certificates, and consolidating your monitoring stack.

RSS feed
uptime incident-response

Website Down? The Exact Checklist to Diagnose and Fix It

Your website is down. A triage runbook: confirm it's real, isolate DNS vs TLS vs server vs app with actual commands, and keep users informed.

6 min read
security-headers hsts

HSTS Explained: max-age Strategy, includeSubDomains Pitfalls, and the Preload List

A practical HSTS guide: how Strict-Transport-Security works, ramping max-age safely, includeSubDomains pitfalls, preloading, and copy-paste configs.

6 min read
status-page incidents

Status Page Best Practices: What a Good Public Status Page Looks Like

What separates a status page customers trust from an always-green wall nobody believes: component granularity, honest history, update cadence, and branding.

6 min read
email-security dmarc

Moving DMARC from p=none to p=reject: the Safe Migration Path

How to move a DMARC policy from p=none to quarantine to p=reject safely, with aggregate reports, pct= ramping, forwarder breakage and a realistic timeline.

6 min read
uptime monitoring

Uptime Monitoring Best Practices: Intervals, False Positives, and What 99.9% Actually Means

Check intervals, confirmation checks, keyword assertions, alert routing and what 99.9% really means. A practical uptime monitoring guide for 2026.

6 min read
security-headers csp

The Complete Guide to HTTP Security Headers in 2026

The HTTP security headers that matter in 2026 (CSP, HSTS, X-Frame-Options, Permissions-Policy, COOP/COEP), with copy-paste nginx, Apache & Caddy configs.

7 min read
performance ttfb

Why Is My Website Slow? Diagnosing Latency Layer by Layer

DNS, TLS, TTFB, download and front-end weight. A layer-by-layer method for finding where your page's time goes, starting with one curl command.

6 min read
checklist dns

The January Infrastructure Audit: A Checklist for Everything You've Been Ignoring

Expiring domains, stale DNS records, untested backups, orphaned access. The once-a-year infrastructure audit that prevents this year's outages.

6 min read
outages aws

AWS in October, Cloudflare in November: Two Outages, One Lesson About Hidden Dependencies

A DynamoDB DNS race in us-east-1 and an oversized Cloudflare config file took down much of the web within a month. What both teach about hidden dependencies.

6 min read
peak-season checklist

The Peak Season Readiness Checklist: Three Weeks to Black Friday

Black Friday is three weeks out. Code freeze, certificate sweeps, load tests, tighter checks and on-call rotas, ordered by lead time.

6 min read
monitoring keyword-checks

The Page Loads, But It's Broken: Catching Failures That Return 200

Soft failures (blank pages, dead checkouts, APIs returning errors with status 200) slip past status-code monitoring. Content assertions catch them.

6 min read
incidents postmortems

Blameless Postmortems for Small Teams — A Practical Template

Why blame corrupts incident timelines, how to rebuild them from monitoring data, the five-whys trap, and a copy-paste postmortem template for small teams.

6 min read

Browse by topic

Monitor your site — free

Uptime, SSL, DNS, security-header grades and SPF/DKIM/DMARC — one dashboard, one bill. The free tier includes the security layer and allows commercial use.