Troubleshooting

Start with the status, the last-check time, and the check details. Then compare the result with the free tools from the same public perspective.

The endpoint is in error

An error means the check itself could not complete, for example because of a refused connection, DNS failure, timeout, or invalid chain. Failed checks appear on the dashboard but do not dispatch an alert, because transient network failures are common. Investigate the target, then confirm recovery with a fresh check.

The certificate is warning, critical, or expired

  1. Confirm which hostname and port are serving the certificate, including SNI and any proxy layer.
  2. Renew or replace the certificate through your certificate-management workflow.
  3. Install the complete chain, not only the leaf certificate.
  4. Verify the deployed result from outside the service with the checker.

The certificate identity changed

CertWatch detects an unexpected issuer or subject change even when the new certificate is not near expiry. Confirm whether a deployment, CA migration, proxy change, or compromise explains it. If the target was intentionally changed, edit the monitored endpoint so its new identity becomes the comparison baseline.

The domain is unsupported or has unexpected registration data

Some TLDs do not publish an RDAP server in IANA's bootstrap data. That is a coverage gap, not proof that the domain is down. For supported domains, compare the registration result with the registrar's authoritative account and confirm the renewal date and transfer settings there.

No alert arrived