All features
Intelligence

External change detection for DNS, TLS, HTTP fingerprints and content

Most incidents start with a change nobody announced. PulseTrace fingerprints what your endpoints look like from outside — DNS answers, the certificate chain, response headers, redirects, page content, infrastructure — on every check, and opens a change event the moment any of it differs.

A fingerprint is a structured snapshot: the resolved IPs and their reverse DNS, the certificate and its issuer, the server and security headers, the redirect chain, a content hash. Each check diffs the new snapshot against the last one and classifies the difference — a new redirect, a swapped certificate, a removed header, a moved A record — with a severity.

Changes live on the Intelligence timeline, filterable by category, with before/after detail. Suppression rules silence expected churn (a rotating CDN IP, a nightly content change) so what remains is signal. On Pro, the correlation engine links changes that happened together across monitors.

  • Five categories — DNS, TLS, HTTP fingerprint, content, infrastructure.
  • Before / after detail on every event.
  • Suppression rules for churn you expect.
  • Correlation (Pro) groups simultaneous changes across monitors into one story.
app.pulsetrace.app · change detection

How it works

  1. 1Turn on change intelligence for a monitor (it's on by default for HTTP, TLS and DNS types on Team+).
  2. 2Every check snapshots the external surface and diffs it against the previous one.
  3. 3Significant changes alert your destinations and can open incidents; the rest wait on the timeline.

Plan availability

Team and above · correlation engine, Certificate Transparency and look-alike watch on Pro and above.

Compare plans →

Monitor types that use it

Questions about change detection

Will a CDN rotating IPs flood me with changes?
Infrastructure changes are classified below the alert threshold by default, and a suppression rule can silence a category or a specific pattern for a monitor.
Can a change open an incident?
Yes — incident rules can key off a change of a given severity, so a certificate swap or a new redirect on your checkout endpoint pages the on-call.