Vigil
Know, with evidence, whether a website really works: layered DNS, TCP, TLS, HTTP and real-browser checks for one link or thousands, with a verdict, a confidence score and the reason for every one.

85
links from a messy spreadsheet checked in 52 s
95.9%
average confidence across the verdicts
9
verdicts plus 17 issue flags, each with a written reason
125
backend tests, green on Linux and Windows
Inside the product
See it working
Real screens and a recorded run, captured from the working product.
Live run on a real PC: the check screen.
01 / 24My role
Sole engineer: the verification engine, the run manager, the reports and the bilingual interface.
The problem
A status code is not an answer. Plenty of "dead" links open fine in a browser, and plenty of 200 OK pages are parked domains, empty pages, server welcome pages or "not found" pages in disguise. Simple link checkers either cry wolf or miss real problems, and when your own connection drops they mark a thousand healthy sites as dead.
What I built
Vigil collects independent evidence and only calls a link dead when the layers agree. Each address is normalised (missing schemes, www, Arabic and other international domains, stray punctuation, duplicates) and checked as given first. DNS failures get a second opinion from independent resolvers, HTTP follows redirects and fingerprints the content, TCP and TLS diagnostics explain connection and certificate problems, and anything still unclear, such as a bot challenge or a JavaScript-only page, goes to a real browser.
When the original address fails, Vigil tries the other scheme, the www variant and the site root and reports which one works. Failures are re-checked at low pressure before they are trusted, and canary checks pause the run if the machine itself goes offline. A site that only opens with certificate checks turned off (expired, self-signed or issued for another name) gets its own "certificate problem" verdict, and the reason names the problem. Every link ends with one of nine verdicts plus issue flags, a confidence score, a plain-language reason in English or Arabic and the full probe timeline.
Architecture
A Python FastAPI engine with httpx (HTTP/2), dnspython, cryptography for certificate details, selectolax for content analysis and Playwright Chromium for the browser layer. Runs live in SQLite, survive restarts and resume where they stopped; an adaptive governor keeps CPU and memory under their ceilings and a per-host limit keeps runs polite. A Next.js 16 static interface with React 19, Tailwind CSS 4 and Motion is served by the API and streams progress over server-sent events. Links come in from pasted text, spreadsheets, a web page, a sitemap, a REST API or a CLI.
Challenges
Telling apart the many ways a site can look broken or healthy without being so: bot challenges, rate limits, soft 404s, login walls, maintenance pages, parked domains, expired or self-signed certificates and JavaScript-only apps. Keeping very large runs fast, with a server-side filtered results table and reports that open safely in Excel.
Key engineering decisions
Use the cheapest layer that gives a sure answer and escalate to a real browser only when needed. Never hide a failure behind a working variant: report both. Neutralise spreadsheet formula injection in exports and protect the API against DNS rebinding.
Results & impact
On a CRM-style spreadsheet of 85 rows written the way people write addresses (with and without https, bare domains, www names, an Arabic domain, duplicates and a typo) against 30 test sites that reproduce real-world cases, Vigil found the address column on its own and finished in 52 s with an average confidence of 95.9%. It caught a payment page behind a bot challenge (decided by the real browser), a rate-limited API, a soft 404, expired, self-signed and soon-expiring certificates, a redirect loop, a login wall and a domain that only works with www. The same file through the CLI gave identical counts.
Highlights
- Every way to bring links in: paste any text, upload spreadsheets and many file types, extract links from a page, expand a sitemap, REST API and CLI
- Layered verification: DNS with a second opinion, TCP, TLS, HTTP with content analysis and a real browser only when needed
- 9 verdicts, 17 issue flags, a confidence score and a written reason with the evidence for every link
- Fallback variants that explain failures without hiding them
- Verify pass for failures and canary checks that pause the run when the machine goes offline
- Live run view with progress, speed, time left, verdict donut, attention list and site ranking
- Reports as styled multi-sheet XLSX, CSV, JSON with full evidence or a standalone HTML page, in English or Arabic
- First-class Arabic interface with RTL, light and dark themes and reduced-motion support
- Tested live on hard cases (a bot wall, a parked domain, a domain that does not exist) and on a 5,210-link spreadsheet of news sites, whose Excel report exported in about 3 s

