{"id":374856,"date":"2026-09-25T08:51:48","date_gmt":"2026-09-25T08:51:48","guid":{"rendered":"https:\/\/de.wordpress.org\/plugins\/domainwarn-monitoring-for-domains-certificates-and-email\/"},"modified":"2026-10-10T05:50:38","modified_gmt":"2026-10-10T05:50:38","slug":"domainwarn","status":"publish","type":"plugin","link":"https:\/\/af.wordpress.org\/plugins\/domainwarn\/","author":23572941,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.2","stable_tag":"1.3.2","tested":"7.1.3","requires":"6.3","requires_php":"8.2","requires_plugins":null,"header_name":"DomainWarn Monitoring","header_author":"Wigandt Technology","header_description":"Monitors availability, certificate, DNS and email deliverability of your site \u2013 and reports what is invisible from outside: outdated plugins, a stalled WP-Cron.","assets_banners_color":"3f97c7","last_updated":"2026-10-10 05:50:38","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/domainwarn.com","header_author_uri":"https:\/\/wigandt.tech","rating":0,"author_block_rating":0,"active_installs":0,"downloads":209,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.0":{"tag":"1.1.0","author":"wigandt","date":"2026-09-25 08:51:39","revision":3712703},"1.2.0":{"tag":"1.2.0","author":"wigandt","date":"2026-10-01 06:31:18","revision":3722494},"1.3.0":{"tag":"1.3.0","author":"wigandt","date":"2026-10-01 12:05:25","revision":3723073},"1.3.1":{"tag":"1.3.1","author":"wigandt","date":"2026-10-01 14:52:18","revision":3723362},"1.3.2":{"tag":"1.3.2","author":"wigandt","date":"2026-10-10 05:50:38","revision":3737639}},"upgrade_notice":{"1.3.2":"<p>security.txt is served directly instead of redirected, plus fixes for multisite, connecting and the dashboard widget.\nNothing to set up.<\/p>","1.3.1":"<p>Fixes for the heartbeat, network activation and connecting. Nothing to set up.<\/p>","1.3.0":"<p>New dashboard widget with availability, response time and expiry dates of your domains. Nothing to set up.<\/p>","1.2.0":"<p>Requires PHP 8.2 or newer. Optional: serve security.txt via DomainWarn, and see the state of MTA-STS and BIMI on\nthe settings page. Nothing changes until you switch it on.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3712702,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3712702,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3712702,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3712702,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.0","1.2.0","1.3.0","1.3.1","1.3.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3712702,"resolution":"1","location":"assets","locale":"","width":2200,"height":1452},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3712702,"resolution":"2","location":"assets","locale":"","width":2200,"height":1564}},"screenshots":{"1":"Settings \u2192 DomainWarn: the addresses of this site, one button to connect, and the client the domains are assigned to.","2":"After the connection test: the plugin names the organization the token belongs to."}},"plugin_section":[262246],"plugin_tags":[14328,48588,5603,1536,29148],"plugin_category":[54],"plugin_contributors":[282680],"plugin_business_model":[],"class_list":["post-374856","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-dns","plugin_tags-email-deliverability","plugin_tags-monitoring","plugin_tags-ssl","plugin_tags-uptime","plugin_category-security-and-spam-protection","plugin_contributors-wigandt","plugin_committers-wigandt"],"banners":{"banner":"https:\/\/ps.w.org\/domainwarn\/assets\/banner-772x250.png?rev=3712702","banner_2x":"https:\/\/ps.w.org\/domainwarn\/assets\/banner-1544x500.png?rev=3712702","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/domainwarn\/assets\/icon-128x128.png?rev=3712702","icon_2x":"https:\/\/ps.w.org\/domainwarn\/assets\/icon-256x256.png?rev=3712702","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/domainwarn\/assets\/screenshot-1.png?rev=3712702","caption":"Settings \u2192 DomainWarn: the addresses of this site, one button to connect, and the client the domains are assigned to."},{"src":"https:\/\/ps.w.org\/domainwarn\/assets\/screenshot-2.png?rev=3712702","caption":"After the connection test: the plugin names the organization the token belongs to."}],"raw_content":"<!--section=description-->\n<p>A site is not only broken when the page stays white. It is also broken when no order confirmation has gone out for\nthree days because WP-Cron has stalled. Or when the certificate expires in two weeks and nobody read the issuer's\nemail. Or when a plugin has been carrying a known vulnerability for months.<\/p>\n\n<p><a href=\"https:\/\/domainwarn.com\">DomainWarn<\/a> monitors your domains from the outside \u2013 availability, redirects, TLS\ncertificate, DNS, SPF, DKIM, DMARC, blacklists, domain expiry. This plugin adds the inside view that nobody can see\nfrom outside.<\/p>\n\n<h4>What the plugin does<\/h4>\n\n<ul>\n<li><strong>Adds the addresses of this site<\/strong> to monitoring. In a network, every site.<\/li>\n<li><strong>Reports what is invisible from outside<\/strong>: the exact WordPress and PHP version, plugins and themes with a pending\nupdate, the mail setup \u2013 sender address and server. Together with the DNS records this yields the finding \"your\nsite sends through a server that is not in the SPF record\", which neither the site nor an outside check can reach\non its own.<\/li>\n<li><strong>Notices when WP-Cron stalls.<\/strong> A scheduled run reports in every 15 minutes. If it stops, WP-Cron has stalled:\nthe site still answers, but no mail goes out and nothing is processed. DomainWarn then opens an incident and sends\nit to your channels \u2013 email, Slack, Teams or webhook.<\/li>\n<li><strong>Serves security.txt via DomainWarn<\/strong> (optional, off by default). If DomainWarn hosts the security.txt of your\ndomain, the site fetches it from there and serves it itself at \/.well-known\/security.txt \u2013 no redirect \u2013 and the\nmandatory Expires field stays current by itself. The file is kept for an hour; while DomainWarn cannot be reached,\nthe site serves the last good copy as long as it has not expired. Only at the domain itself or with www in front\nof it, only from DomainWarn, and never over a security.txt that is already there: a file in the web root or\nanother plugin is shown as a conflict instead of being overridden.<\/li>\n<li><strong>Shows the state of the site on the dashboard<\/strong>: a \"DomainWarn\" widget with availability over 30 days, the\nresponse time of the last 7 days as a small chart, certificate and domain expiry and open incidents \u2013 for every\ndomain of the site, with a link to it in DomainWarn. The figures are refreshed by the scheduled run at most once\nan hour; opening the dashboard never contacts DomainWarn.<\/li>\n<li><strong>Shows what DomainWarn hosts for the domain<\/strong>: the state of security.txt, MTA-STS and the BIMI logo, the DNS\nrecords to copy, and a link to the page in DomainWarn where they are set up with one click.<\/li>\n<li><strong>Works from the command line<\/strong> as well: <code>wp domainwarn test<\/code>, <code>wp domainwarn sync<\/code>, <code>wp domainwarn report<\/code>.<\/li>\n<\/ul>\n\n<h4>Which data is transmitted<\/h4>\n\n<p>The plugin sends to DomainWarn: the addresses of the site, the WordPress and PHP version, the names and versions of\ninstalled plugins and themes, the sender address and mail server, and whether maintenance mode is on.<\/p>\n\n<p><strong>Not transmitted<\/strong> are users, posts, comments, orders or any content of the site. The API token is stored on the\nsite only and never reaches the browser. The plugin works with a DomainWarn account only; the processing is\ndescribed in DomainWarn's <a href=\"https:\/\/domainwarn.com\/legal\/privacy\">privacy policy<\/a>.<\/p>\n\n<h4>External service<\/h4>\n\n<p>This plugin connects to the DomainWarn API at <code>https:\/\/api.domainwarn.com<\/code> (operated by Wigandt Technology,\nGermany). Without an API token that you create yourself, the plugin stays idle and contacts nothing. The API\naddress is configurable, DomainWarn can also be self-hosted.<\/p>\n\n<p>If you switch on \"Serve security.txt via DomainWarn\", the site fetches the file from\n    https:\/\/domainwarn.com\/security-txt\/\u2026 when someone requests \/.well-known\/security.txt \u2013 at most once an hour \u2013 and\nserves it itself. Normal page views never contact DomainWarn: the address of the file is stored on the site and\nrefreshed by the scheduled run.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Under Settings \u2192 DomainWarn, click \"Connect with DomainWarn\". You confirm in DomainWarn, and the token lands\nhere by itself. A free account is enough to start.<\/li>\n<li>\"Add addresses\". Done.<\/li>\n<\/ol>\n\n<p>Prefer to do it by hand? Create a token in DomainWarn under Settings \u2192 API with write scope and paste it into the\ntoken field instead.<\/p>\n\n<p>For the heartbeat, WP-Cron must run \u2013 which is exactly what it checks.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20paid%20account%3F\"><h3>Do I need a paid account?<\/h3><\/dt>\n<dd><p>No. The plugin is free and works with the free DomainWarn account. What is charged is the monitoring service, once\nmore domains or shorter check intervals are needed.<\/p><\/dd>\n<dt id=\"is%20content%20of%20my%20site%20transmitted%3F\"><h3>Is content of my site transmitted?<\/h3><\/dt>\n<dd><p>No. Transmitted are addresses, versions, installed plugins and themes, sender address and mail server, and the\nmaintenance mode. No users, posts, comments or orders.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20work%20with%20a%20self-hosted%20domainwarn%3F\"><h3>Does the plugin work with a self-hosted DomainWarn?<\/h3><\/dt>\n<dd><p>Yes. The API address can be changed on the settings page.<\/p><\/dd>\n<dt id=\"why%20does%20the%20plugin%20not%20serve%20mta-sts%20as%20well%3F\"><h3>Why does the plugin not serve MTA-STS as well?<\/h3><\/dt>\n<dd><p>The MTA-STS policy belongs on a host of its own \u2013 mta-sts.example.com for example.com \u2013 with its own certificate; a\nrequest there never reaches WordPress, and RFC 8461 forbids following redirects when a mail server fetches the\npolicy. DomainWarn serves it once a CNAME points to it. The plugin shows that record and the TXT record to copy, and\nlinks to the page in DomainWarn that sets both with one click.<\/p><\/dd>\n<dt id=\"why%20does%20domainwarn%20open%20an%20incident%20although%20my%20site%20is%20up%3F\"><h3>Why does DomainWarn open an incident although my site is up?<\/h3><\/dt>\n<dd><p>Because the heartbeat stopped. Then WP-Cron has stalled: the site still answers, but it sends no mail and processes\nnothing.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>security.txt is served by the site itself (status 200, no redirect), kept for an hour, with the last good copy\nwhile DomainWarn cannot be reached. \"Check security.txt\" recognises this and reports an outdated cached copy.<\/li>\n<li>Two installations under one domain (for example kunde.de and blog.kunde.de) each report their own inside view and\nping their own heartbeat.<\/li>\n<li>Multisite: only the main site reports the whole network, and only network admins manage the settings there; a\nsub-site reports just itself. Networks with more than 100 sites are reported in full.<\/li>\n<li>\"Test connection\" and the other buttons on the settings page save the form first instead of dropping a freshly\nentered token.<\/li>\n<li>Opening the settings page in a second tab no longer breaks a connection in progress.<\/li>\n<li>The dashboard widget keeps the figures of the first run.<\/li>\n<li>Sites under internationalised endings such as .\u0440\u0444 are recognised.<\/li>\n<li>Removed the switch \"Add the addresses of this site to DomainWarn\", which had no effect.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Heartbeat: after a 404 the scheduled run sets the heartbeat up again instead of pinging into the void; changing the\ntoken or slug clears the remembered address.<\/li>\n<li>\"Report now\" and <code>wp domainwarn report<\/code> show a notice instead of a fatal error when DomainWarn cannot be reached.<\/li>\n<li>Network activation schedules the run on every site of the network.<\/li>\n<li>Connecting works when the site and the admin run on different hosts.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>New: the \"DomainWarn\" dashboard widget shows, per domain of the site, its state, availability over 30 days, the\nresponse time of the last 7 days, when certificate and domain expire and the open incidents, with a link to the\ndomain in DomainWarn. Only for administrators.<\/li>\n<li>The figures come from the scheduled run, at most once an hour (\"Report now\" and <code>wp domainwarn report<\/code> refresh\nthem right away). Opening the dashboard never contacts DomainWarn.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New: \"Serve security.txt via DomainWarn\" (off by default). The site answers \/.well-known\/security.txt with a\nredirect to the file DomainWarn hosts \u2013 only at the domain itself or www, only to DomainWarn, never over an\nexisting security.txt.<\/li>\n<li>New: \"Check security.txt\" fetches the address like a researcher and shows whether the redirect arrives, whether a\nvalid file waits at the target and whether a file or another plugin answers as well.<\/li>\n<li>New: \"Hosted by DomainWarn\" shows the state of security.txt, MTA-STS and the BIMI logo with the records to copy.<\/li>\n<li>Domain names with umlauts are added in the form DomainWarn uses (Punycode) instead of being skipped.<\/li>\n<li>Requires PHP 8.2. The plugin already relied on PHP 8.2 while declaring 8.1, so on PHP 8.1 it failed with a fatal\nerror. On an older PHP it now stays inactive and says so in the admin area.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>\"Connect with DomainWarn\" sets the connection up with one click \u2013 no token to copy.<\/li>\n<li>\"Assign to client\" is a list of your clients in DomainWarn instead of a free text field.<\/li>\n<li>The organization slug and the API address moved under \"Advanced\".<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>The scheduled run is now really scheduled: on activation the 15-minute interval was not known yet, so no\nheartbeat was ever set up.<\/li>\n<li>Corrected links and contributor in this readme.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release: add addresses to monitoring, report the inside view, heartbeat against a stalled WP-Cron, settings\npage and WP-CLI commands.<\/li>\n<\/ul>","raw_excerpt":"Monitors availability, certificate, DNS and email of your site \u2013 and reports what is invisible from outside: outdated plugins, a stalled WP-Cron.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/374856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=374856"}],"author":[{"embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wigandt"}],"wp:attachment":[{"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=374856"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=374856"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=374856"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=374856"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=374856"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/af.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=374856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}