HTTP and API
How it works. A request from the probe with your method (GET or HEAD unless you explicitly configure otherwise and confirm the endpoint is safe to call repeatedly), headers and encrypted credentials. We check the status code against your expected set, optionally a keyword in the first 128 KiB of the decompressed body and bounded JSON path assertions, and compare latency against your degraded threshold.
What it does not prove. HEAD does not prove GET works, HTTP 200 does not prove a business transaction works, and request timing is not browser rendering performance.
TLS certificates
How it works. Every HTTPS check validates trust, chain and hostname. A separate daily inspection records issuer, SANs, fingerprint, expiry and chain changes and warns at 30, 14, 7, 3 and 1 days. If validation fails, a diagnostic handshake captures the presented certificate as evidence without marking the monitor healthy.
What it does not prove. Private CAs show as untrusted; STARTTLS is not negotiated.
DNS records
How it works. A, AAAA, CNAME, MX, TXT, NS, SOA and CAA lookups through the probe resolver or Cloudflare, Google or Quad9. Answer sets are normalized so ordering and TTL never cause false changes. You can pin expected values or alert on any change.
What it does not prove. Resolver caches mean a change can take up to the TTL to be seen. Lookup failure is reported as unknown, not as missing records.
TCP ports
How it works. A connection to an explicitly permitted port on a public host, timing the connect. No payloads, no banner grabbing, no scanning.
What it does not prove. A successful connect does not mean the service behind the port is healthy.
Heartbeats
How it works. Your job sends a request to a secret URL on start, success or failure. We alert when the expected interval plus grace passes without a signal, when a run exceeds its maximum duration or when it reports failure. Duplicate signals with the same key are accepted once.
What it does not prove. Heartbeats measure that your job reported, not that its output was correct.
Domain expiry
How it works. RDAP lookups through the registry published in the IANA bootstrap file, throttled per registry and cached. Warnings at the thresholds you choose.
What it does not prove. Not every TLD publishes RDAP. Missing data is shown as unavailable, never as expired.