What is actually checked
The availability check that always runs, and twelve you switch on per plan — grouped by the question each answers. Every one says what makes it fail, because a check nobody can interpret is a notification nobody acts on.
On this page
Availability — the one that runs constantly#
An HTTP request on the site’s interval, from every 30 seconds upwards. It records the status code, the time to first byte and the response size. A non-2xx status, a timeout, a refused connection or a TLS failure is a failure, and a failure opens an incident.
The monitor also watches itself. If a pass finds a great many sites failing at once, it treats its own view of the network as suspect and holds the alerts back rather than telling twenty clients they are down because one datacentre link is not. The delay is visible on the health endpoint, and the incidents still open — they are just not announced on a bad measurement.
Content checks — a page that answers but is broken#
- Keyword
- A word or phrase that must be present — or must be absent — in the response body. This is what catches the white screen at HTTP 200: the server answers, the page is empty, and nothing else would notice.
- Redirect chain
- Where the address actually ends up. A site that starts redirecting to a domain it did not use yesterday is the shape of a hijack, and this is what sees it.
- Defacement
- A hash of the page, compared against the one recorded when the check was switched on. It reports that the page changed — not what changed — so it is a prompt to look, not a diff.
- Broken links
- A crawl of the links on a page, reporting the ones that no longer resolve. Weekly rather than constant, because it is a courtesy to somebody else’s server as much as a check on yours.
The two clocks nobody watches#
- TLS certificate
- The expiry date and the validity of the chain, re-read every few hours. You are warned in days, not on the morning it breaks.
- Domain registration
- The registry’s own record, read over RDAP. A domain that lapses takes the site, the mail and the client relationship with it, and it fails on a date that was known a year in advance.
DNS, mail and network#
- DNS records
- A, AAAA, MX and NS, compared against a baseline the product learns over the first few passes. NS and MX are compared exactly — those change rarely and a change is significant. A and AAAA are judged against everything seen before, so a site behind a CDN that answers from a different address every minute does not cry wolf.
- Mail authentication
- SPF, DKIM and DMARC records, plus whether the MX hosts answer at all. A domain whose mail authentication has been removed is one whose invoices start landing in spam.
- TCP port and ping
- Whether a given port accepts a connection, and whether the host answers ICMP.
- API endpoint
- A status code and, optionally, a field in the JSON response — for the endpoint behind the site rather than the page in front of it.
Audits — the ones with an opinion#
- Security headers
- HSTS, CSP, X-Frame-Options, X-Content-Type-Options and Referrer-Policy: which are present and which are missing. Missing headers are not an outage and never open an incident; they are a list to work through with a client, and a good thing to attach to a quote.
- robots.txt and sitemap.xml
- Whether they exist and whether they are readable. A robots.txt that quietly starts disallowing everything is a marketing incident that looks like nothing.
Why a check might not be running#
There are exactly two reasons, and the console says which:
- The plan does not include it
- The twelve optional checks are granted per plan, so you can sell a smaller and a larger tier. Availability is not one of them: it always runs. The site page lists what is covered and what is not — see Billing your clients.
- The hostname is not verified
- The checks that go beyond an ordinary web request — port scanning, ping, mail probing, link crawling — only run on a hostname the workspace has proved it controls, with a DNS record or an uploaded file. Sending that traffic at somebody else’s machine on a stranger’s say-so is not monitoring, and this product will not do it.