Monitoring behavior
Check intervals
| Plan | TLS endpoint interval | Domain interval |
|---|---|---|
| Free | Daily | Daily |
| Starter | Hourly | Daily |
| Pro | Hourly | Daily |
Domain checks run on one daily cadence for every account regardless of plan — registration state doesn't change fast enough to justify hourly polling the way a certificate's remaining lifetime can. Adding or editing an endpoint or domain also triggers an immediate check in the background, so a new entry doesn't sit with an empty status until the next scheduled run.
Statuses
An endpoint or domain always shows one of:
- healthy — nothing due for attention.
- warning — approaching expiry, inside the warning threshold.
- critical — very close to expiry.
- expired — past its expiry date.
- error — the check itself failed (connection refused, invalid chain, DNS failure, etc.).
- unsupported — domains only: the TLD has no RDAP server per IANA's bootstrap list, a coverage gap rather than an outage.
An endpoint also alerts on an unexpected identity change — the certificate's issuer or subject changing without a corresponding edit on your side — independent of the expiry-based statuses above, since a silent swap is exactly the kind of change a renewal reminder alone wouldn't catch.
Check history and retention
| Plan | History retained |
|---|---|
| Free | 30 days |
| Starter | 90 days |
| Pro | 365 days |
Every check is recorded, not just the latest result, so you can see when a certificate was last reissued or when a domain's expiry moved. History older than your plan's retention window is pruned automatically based on your current plan — so downgrading from Pro to Free will retroactively trim stored checks to match the Free plan's 30-day window on the next prune cycle.
Muting
An endpoint can be muted temporarily (for a set number of minutes, up to 30 days) or indefinitely — muting only suppresses alert dispatch; checks, status, and history keep updating regardless, so a muted endpoint's dashboard tile is never stale, only quiet.