Alerts and webhooks
Corrections: support@domainvane.com
Domainvane raises an alert when a certificate or domain registration is close to expiry, when checks keep failing, and once when that incident clears. Alerts appear on the dashboard and are emailed to your account address. On paid plans they are also posted to the webhooks you set up. The exact webhook body is in webhook payload format.
When an alert fires
Threshold. For both the TLS certificate and the domain-registration expiry, an alert fires at 30, 14, 7, and 1 days before the expiry time. The day count is floor((expiry − now) / 86400000) in UTC. A domain row whose RDAP result is unknown has no expiry time, so it gets no threshold alert.
Failure. A failure alert fires only after 3 consecutive failed checks of that kind. One timeout does not trigger it.
Cooldown. The same incident is not sent again for 24 hours. While a condition stays true, the alert can repeat after the cooldown.
Recovery. When a target that was failing or inside an expiry window recovers, Domainvane sends one recovery notice for that incident. The incident id advances when the condition clears, so a later lapse is a new incident.
Paused hostnames count toward the plan cap and are not checked or alerted. Deleting a hostname stops checks and alerts for it.
Checks that can raise a failure include DNS failure, connection refused, timeout, a TLS protocol failure, and the certificate problems in the status list (NOT_YET_VALID, EXPIRED, SELF_SIGNED, CHAIN_INCOMPLETE, HOSTNAME_MISMATCH). Threshold alerts are about the day count. A certificate can be inside 30 days and still be otherwise valid. Those are different alerts.
Where alerts go
| Plan | Generic JSON webhook | Slack-compatible webhook | |
|---|---|---|---|
| Free | Yes | No | No |
| Solo | Yes | One URL | No |
| Agency | Yes | One URL | One URL |
| Agency+ | Yes | One URL | One URL |
Email goes to the address on your account. Email alerts reach external inboxes, including Gmail. Inbox placement is not guaranteed for every provider, so keep the dashboard as your source of truth.
A channel your plan does not include is not contacted. Saving a webhook your plan does not include returns a forbidden response. This is checked on the server, not just hidden in the page.
Agency and Agency+ use the same channels. The difference between them is the hostname cap (150 vs 750) and the report-page cap (50 vs 200), not a different alert schedule. Every plan checks on the same cadence: about 24 hours when healthy, and about 6 hours when the certificate has 7 days or fewer left or a check has already failed.
Set up webhooks
Open Webhooks in the dashboard menu (/settings/webhooks). Solo accounts see one form for the generic JSON webhook. Agency and Agency+ accounts also see a form for the Slack-compatible webhook. For each one you can:
- Save a URL. It must be
httpson port 443, without a username or password, on a publicly reachable host with a valid certificate. - Send test to post a sample body right away and see whether your endpoint accepted it or why it failed, for example
HTTP 404, a timeout, or a redirect. You can send 5 tests every 10 minutes. - Remove the URL. Domainvane stops posting to it, and any retry still waiting for it is cancelled.
The same page shows your account's signing secret, with a Regenerate secret button. Every webhook post carries an X-Domainvane-Signature header made with that secret, so your receiver can check that the post came from Domainvane. Webhook payload format explains how to verify it.
Webhook rules
- The URL is stored encrypted with the server data key. Logs and delivery records keep the host of the URL, not the full URL.
- The URL is checked when you save it and again on every post. A URL that points at a non-public address is not called.
- Any 2xx response counts as delivered. Redirects are not followed: a 3xx response is a failure and is not retried. A 4xx response is a failure and is not retried.
- A 5xx response, a timeout, a DNS failure, or a connection failure gets one retry about 60 seconds later, to the URL saved at that time. There is no second retry. If Domainvane stops in the middle of sending a retry, that retry can be sent again after the restart, so make your receiver tolerate duplicates.
- Webhook posts, including retries and tests, count toward a service-wide hourly limit on outbound webhook requests. A post over that limit is recorded as failed and is not retried.
- The Slack option is a compatible incoming-webhook URL, not a Slack app install.
- After a downgrade, a saved URL your new plan does not include is kept encrypted but not used.
There is no public API and there are no API keys in this version. You cannot create a key to pull alerts, add hostnames, or read the dashboard from your own script. Domainvane calls the URL you configure. You do not call Domainvane.
The billing endpoint that the payment provider calls is a separate, internal adapter. It is not a customer webhook and it is not an API you can build on.
What you should expect in practice
A healthy certificate with 40 days left produces no alert. The 30-day alert fires on the check that first sees the day count at or under 30. Healthy checks run about daily, so the alert arrives on the day the check sees the threshold, not at a clock time you pick.
A renewal that completes before the next check produces a recovery notice if an incident was open.
If RDAP returns unknown, watch the dashboard for that word. Do not treat a missing domain alert as proof the registration is fine. See getting started for how unknown differs from an error.
Related
- Webhook payload format: the JSON and Slack bodies, the fields, and signature verification
- Bulk adding: paused names, caps, and
limit - Client report pages: a read-only page is not an alert channel