BigCommerce SSL goes through Fastly CDN.
A client DNS change breaks the CNAME. Renewal stops.
BigCommerce agencies managing custom domains deal with Fastly CDN SSL that breaks silently when clients change their DNS registrar or add a Cloudflare proxy. Multi-Storefront maps multiple brand domains from one account — each with independent SSL. Headless Catalyst deployments on Vercel or Netlify add a second SSL layer outside the BigCommerce platform that expires on a separate schedule. Merlonix monitors SSL and DNS across the full BigCommerce stack.
No credit card either way — start free, or trial the full workspace.
- Check cadence (Agency)
- 1 min
- SSL pre-expiry alert
- 30 days
- Encrypted DNS lookups
- DoH
- Vendors watched
- 11
Where BigCommerce agencies get caught out
Three failure modes specific to BigCommerce agencies managing custom domains, Multi-Storefront, and headless deployments.
BigCommerce agencies deal with Fastly CDN SSL that breaks silently after client DNS changes, Multi-Storefront brand domain SSL that expires independently across each mapped storefront, and headless Catalyst deployment SSL that carries a separate certificate outside the BigCommerce platform with no native monitoring.
Fastly CNAME break stops SSL renewal
A registrar change or Cloudflare proxy breaks the Fastly CNAME path, so BigCommerce cannot renew the certificate
BigCommerce stores on custom domains use a CNAME record pointing to BigCommerce's Fastly CDN endpoint. BigCommerce manages the SSL certificate through Fastly and renews it automatically as long as that CNAME delegation stays intact. When a client moves their domain to a new registrar and the DNS zone is rebuilt without the Fastly CNAME, or when a client enables Cloudflare's orange-cloud proxy which terminates TLS before the request reaches Fastly, the SSL renewal path breaks. BigCommerce marks SSL provisioning as failed, but the existing certificate continues serving until it expires. The agency discovers the failure when the BigCommerce dashboard shows an SSL error or when the client reports a storefront security warning — which may be weeks after the DNS change that caused the failure.
Multi-Storefront certs expire separately
Each Multi-Storefront brand domain has independent SSL that expires on its own schedule
A BigCommerce agency building a B2B and a D2C storefront for a manufacturer client — trade.clientbrand.com for wholesale buyers and shop.clientbrand.com for retail — manages two independent SSL certificates from the same BigCommerce account. The trade storefront SSL was provisioned first and has a different expiry date than the retail storefront. If the B2B storefront receives less traffic and the agency's monitoring only covers the primary D2C store, the trade.clientbrand.com certificate expires without any proactive alert. When wholesale buyers report that the login page shows an SSL error, the agency must identify which storefront, which domain, and which certificate — instead of receiving an automated alert 30 days before the expiry date.
Headless frontend SSL is a second layer
Headless Catalyst frontends on Vercel or Netlify carry their own SSL that expires separately
A headless BigCommerce storefront where Catalyst runs on Vercel and the BigCommerce API serves product and cart data has two independent SSL paths: the Vercel SSL for the frontend domain and the BigCommerce Fastly SSL for the backend. The Vercel SSL renews automatically as long as the frontend domain's CNAME record continues to resolve to Vercel's edge network. When the agency migrates the Vercel project to a different team account or the client updates their DNS configuration, the Vercel SSL renewal fails silently. The storefront continues serving from Vercel's CDN cache, masking the SSL failure until cache invalidation — at which point visitors see a certificate error on the main storefront domain without any forewarning.
How it works
SSL and DNS monitoring for BigCommerce agencies across SaaS storefronts, Multi-Storefront brand domains, and headless deployments.
Merlonix monitors CNAME integrity and SSL health across every BigCommerce custom domain — including Multi-Storefront secondary brand domains and headless Catalyst frontends on Vercel — and catches Fastly CDN SSL renewal failures before client storefronts return certificate errors.
01
Add BigCommerce store domains, Multi-Storefront brand domains, and headless frontend endpoints
Verify ownership with a DNS TXT record on the apex domain. All subdomains under that apex — Multi-Storefront secondary brand domains, API subdomains for headless deployments, and checkout endpoints — are added without additional verification. Monitoring secondary brand storefronts catches Multi-Storefront SSL expiry before clients in wholesale or regional markets report errors. Under two minutes per client.
02
CNAME integrity checks on BigCommerce Fastly CDN delegations and headless deployment edge networks
A DNS-over-HTTPS resolver checks every CNAME delegation on every monitoring interval. When a client changes DNS registrar and the new DNS zone is missing the Fastly CNAME that BigCommerce SSL depends on, the mismatch is detected immediately. When a client enables Cloudflare's orange-cloud proxy on the BigCommerce domain, breaking the Fastly SSL path, the CNAME change surfaces in the next monitoring interval. When a headless Catalyst deployment migrates to a new Vercel team and DNS is updated, any CNAME change on the frontend domain is detected before the Vercel SSL renewal fails.
03
SSL monitoring 30 days before expiry across all BigCommerce storefronts, brand domains, and headless endpoints
Full SSL chain validation on every BigCommerce custom domain, Multi-Storefront secondary brand domain, and headless frontend deployment. An expiry alert fires 30 days before the certificate expires — enough lead time to identify whether the failure is a CNAME drift issue, a Cloudflare proxy conflict, or a Vercel project migration, and correct the DNS configuration before customers see a storefront certificate error. Checkout subdomains and API endpoints are monitored on the same 30-day schedule as the primary storefront.
04
Vendor status for BigCommerce, Fastly, and common headless deployment platforms
Merlonix monitors BigCommerce, Fastly, Vercel, and Netlify status alongside client SSL and DNS. When a Fastly infrastructure incident causes SSL validation failures across multiple BigCommerce client storefronts simultaneously, you see the vendor event — not a cascade of individual client alerts that each require separate investigation to determine whether the cause is a client DNS change or a platform-wide CDN incident.
What the numbers mean for BigCommerce agencies
Monitoring built for BigCommerce agencies where one client can mean multiple storefronts, brand domains, and a headless frontend — each with independent SSL.
BigCommerce agencies running Multi-Storefront for multi-brand clients need SSL monitoring that covers every mapped storefront domain — because a secondary brand certificate expiring blocks that storefront while the primary store is unaffected, and Fastly CDN SSL failures after client DNS changes are silent until the certificate runs out.
< 10 min
Time from DNS change to alert — catches Fastly CNAME breaks caused by client DNS registrar migrations and Cloudflare proxy changes before the BigCommerce SSL certificate expires and storefront customers see a security warning
30 days
SSL expiry warning lead time — enough time to identify CNAME drift, correct DNS configuration, or re-provision BigCommerce or Vercel SSL before Multi-Storefront brand domains or headless frontends return certificate errors to customers
11 vendors
Upstream services monitored — BigCommerce, Fastly, Vercel, and Netlify included to distinguish platform incidents from individual client DNS changes affecting BigCommerce storefront SSL renewals
250 assets
Maximum monitored domains on the Agency plan — covers primary storefronts, Multi-Storefront brand domains, headless frontend endpoints, and API subdomains across a full BigCommerce client portfolio
Pricing
Flat monthly fee. Every Multi-Storefront brand domain and headless endpoint included.
No per-domain charges. No per-storefront fees. Pick the tier that fits your BigCommerce client count and monitor every custom domain without billing surprises.
Starter
For individual BigCommerce developers managing a small client portfolio on the SaaS platform.
$19/ month
- 15 monitored assets
- 3 seats
- 5 min check cadence
- SSL + DNS + vendor monitoring
- Email + Slack alerts
Team
For BigCommerce agencies managing Multi-Storefront clients and headless deployments.
$79/ month
- 60 monitored assets
- 10 seats
- 1 min check cadence
- SSL + DNS + vendor monitoring
- Email + Slack alerts
Agency
For agencies with a full BigCommerce client roster across SaaS storefronts and Catalyst headless builds.
$199/ month
- 250 monitored assets
- Unlimited seats
- 1 min check cadence
- SSL + DNS + vendor monitoring
- Email + Slack alerts
Compliance
For regulated-vertical teams that need continuous, audit-ready evidence.
$699/ month
- 500 monitored assets
- Unlimited seats
- 1 min check cadence
- SSL + DNS + vendor monitoring
- Email + Slack alerts
Beyond uptime
More than a 200 OK on every client site
The same account also watches the infrastructure and reputation layers a standard uptime check never reaches — each a live check you can turn on.
Turn monitoring into revenue
Resell client-ready reports as your own
Monitoring doesn’t have to be a cost line. Package the branded report and white-label status page as a deliverable in your retainer — the tooling underneath stays invisible, so to the client the work is yours.
Reports under your brand
Hand each client a polished SSL, DNS, and security report carrying your agency’s name and logo — not ours.
Status pages on their domain
Publish a live status page at status.theirbrand.com with automatic TLS and no “Powered by Merlonix” badge.
Your margin to keep
You pay one add-on cost and package it into the retainer you already bill. The markup — and the margin — are yours.
Common questions
Frequently asked questions
Do I need DNS or registrar access to my clients’ domains to monitor them?
No. Merlonix monitors from the outside in — it probes each domain’s public SSL certificate, DNS records, WHOIS/registration data, and HTTP responses the same way a browser or DNS resolver would. You add an asset by its hostname; no access to the client’s registrar, DNS provider, or servers is required.
What does Merlonix actually check on each site?
Every monitored asset gets continuous SSL-certificate (expiry, issuer, and chain changes), DNS-record, domain-registration/expiry, and uptime monitoring by default. You can also enable infrastructure and reputation checks a standard uptime monitor never reaches — security headers, DNSSEC/DANE, domain-hijack/registrar-lock, blocklist, and cron/heartbeat monitoring — each a live check you turn on per asset.
How often does it check, and how do alerts reach me?
Checks run on your plan’s cadence — as often as every 1 min on Team and above, and every 5 min on Starter. When a certificate, DNS record, registration, or response changes, you get an alert by email and Slack. Alerts fire on real state changes between definitive checks, not on a transient blip.
How much does it cost, and is there a free option?
Yes — there is a free $0 plan (no credit card) to watch a small number of assets, and paid plans start at $19/mo (Starter). You can also start a 14-day full-workspace trial with no card. See the pricing grid above for the assets, seats, and check cadence on each tier.
Know when a BigCommerce store domain or Fastly SSL is about to fail.
Add your first BigCommerce client domain in under two minutes. Multi-Storefront brand domains and headless Catalyst endpoints are monitored from the same dashboard. 14-day trial, no card required.