Troubleshooting
Start with the status, the last-check time, and the check details. Then compare the result with the free tools from the same public perspective.
The endpoint is in error
An error means the check itself could not complete, for example because of a refused connection, DNS failure, timeout, or invalid chain. Failed checks appear on the dashboard but do not dispatch an alert, because transient network failures are common. Investigate the target, then confirm recovery with a fresh check.
The certificate is warning, critical, or expired
- Confirm which hostname and port are serving the certificate, including SNI and any proxy layer.
- Renew or replace the certificate through your certificate-management workflow.
- Install the complete chain, not only the leaf certificate.
- Verify the deployed result from outside the service with the checker.
The certificate identity changed
CertWatch detects an unexpected issuer or subject change even when the new certificate is not near expiry. Confirm whether a deployment, CA migration, proxy change, or compromise explains it. If the target was intentionally changed, edit the monitored endpoint so its new identity becomes the comparison baseline.
The domain is unsupported or has unexpected registration data
Some TLDs do not publish an RDAP server in IANA's bootstrap data. That is a coverage gap, not proof that the domain is down. For supported domains, compare the registration result with the registrar's authoritative account and confirm the renewal date and transfer settings there.
No alert arrived
- Failed checks are dashboard-only and do not trigger alerts.
- Confirm the notification email is verified and current.
- Check whether the endpoint is muted. Muting suppresses dispatch but does not stop checks or history.
- For Slack or generic webhooks, confirm the plan supports the channel and that the destination still accepts requests.
- Review the dashboard result and alert history before treating the absence of an email as proof that monitoring stopped.