SurfaceWatch

DOCS & GUIDE

Using SurfaceWatch

From install to a graded, fixable report in under a minute — plus what each of the six layers means, how to watch a site, and exactly what the extension sends.

1. Install

Add SurfaceWatch from the Chrome Web Store. It works in Chrome and Chromium browsers (Brave, Edge, Vivaldi, Opera). Nothing to configure — the free tier is ready immediately.

2. Run your first check

Open any website, then click the SurfaceWatch icon in your toolbar and hit Check this site. In about 10 seconds you get a full report. The checks are passive — SurfaceWatch only reads what's already public, so it's safe to run on sites you don't own.

3. Read the A–F grade

You get a score out of 100 and a letter grade (A to F), plus how it changed since your last check. Every finding is sorted by severity:

4. Apply the exact fix

Open any issue and SurfaceWatch shows the precise fix, with a tab for your platform — nginx, Apache, Netlify, Vercel, Express or your DNS. For missing headers, use "Fix all header issues at once" to get a single snippet that adds every one. Copy, paste, deploy.

Everything except Content-Security-Policy is safe to paste as-is. For CSP, ship it in Content-Security-Policy-Report-Only mode first and tune it — a strict policy can break your own scripts. SurfaceWatch flags this.

5. The six layers it checks

6. Watch a site & score changes

Add a site to your watchlist and SurfaceWatch re-checks it and shows how its grade changes over time. Free covers 1 site; Pro covers 25 with alerts.

7. Pro — for agencies & freelancers

Pro ($7/mo or $59/yr, 7-day free trial) adds the things client work needs: monitor 25 sites with alerts, bulk-check 25 sites at once with CSV export, see all subdomains, a score-history chart, and branded PDF & JSON reports with your logo and the client's name. You upgrade inside the extension.

8. Privacy — what it sends

SurfaceWatch has no server of its own and runs no analytics or tracking. To do its checks it makes a few lookups to public data sources: domain names go to Google Public DNS (for SPF/DMARC/CAA) and to crt.sh (for public subdomains). Your results, watchlist and settings stay in your browser. Full detail on the privacy page.

Add to Chrome — free