Getting started with Domainvane

Corrections: support@domainvane.com

Domainvane watches the hostnames you add. For each one it checks the TLS certificate on port 443 and looks up domain-registration expiry with RDAP. Results and alert state appear on the dashboard, and alerts are emailed to your account address. Email alerts reach external inboxes, including Gmail; inbox placement is not guaranteed for every provider. Domainvane does not renew the certificate and it does not renew the domain.

Support: support@domainvane.com.

Create the account

Sign up with an email address and a password of 10 to 128 characters. The account stores a scrypt hash of the password. One account is one login. Team seats and multi-user organizations are outside this version.

After signup you land on a dashboard that lists your targets, the latest TLS status, days until certificate expiry, the domain-expiry status, and how many hostnames your plan is using. A hostname that has not been checked yet shows as pending.

Add a hostname

Add one hostname, or paste many. See bulk adding for the paste rules.

Domainvane normalizes each name before it stores it: lowercase, internationalized names converted to punycode, and any scheme or path stripped. The stored target is that hostname on port 443. The same account cannot store the same hostname and port twice. A second add of a name you already monitor is a duplicate and creates no new row.

These inputs are rejected, with a validation message and no row created:

  • an empty value
  • a value that contains spaces
  • characters that are not valid in a DNS hostname
  • a bare IP address
  • a label that is too long

You do not prove control of the name with a DNS record or a file on the site. Add only names you are allowed to monitor. Names that resolve only to non-public addresses are not connected to.

What a check looks at

Certificate (port 443). Domainvane connects with the hostname as the TLS server name. It records notBefore and notAfter, days until expiry, issuer, subject, whether the hostname matches a name on the certificate, and whether the chain the server sent validates against Node's bundled root store. Domainvane does not download missing intermediate certificates, so a server that leaves one out is reported as CHAIN_INCOMPLETE even if some browsers paper over it. Days until expiry are floor((notAfter − now) / 86400000) in UTC. A wildcard matches exactly one label and does not match the bare parent domain. The raw certificate chain is not stored.

The first matching TLS status is the one you see, in this order: DNS_FAIL, CONN_REFUSED, TIMEOUT, TLS_PROTOCOL, NOT_YET_VALID, EXPIRED, SELF_SIGNED, CHAIN_INCOMPLETE, HOSTNAME_MISMATCH.

Domain registration (RDAP). Domainvane asks the RDAP service for that TLD over HTTPS. When the response contains an expiration event, the dashboard shows the date and where it came from: registry or registrar, plus the RDAP server that answered. Those two dates can differ from each other and from the date on a registrar's billing screen. Domainvane shows the provenance so you can see which one you are looking at.

The result is unknown when the TLD is not supported, the bootstrap has no HTTPS RDAP base for that TLD, the expiry is missing, or the data is ambiguous. Domainvane does not guess a date. A timeout, a rate limit from the RDAP server, or a malformed response is stored as an error, which is separate from unknown. Common gTLDs that publish an HTTPS RDAP service are in scope. Other TLDs show unknown. WHOIS is not queried, and port 43 is never opened.

How often checks run

A healthy target is checked again about 24 hours later, plus up to 60 minutes of jitter. A target with 7 days or fewer until certificate expiry, or with at least one failed check in a row, is checked again about 6 hours later, plus up to 15 minutes of jitter. The schedule is the same on every plan. A paused hostname is not checked.

Alerts

Alerts fire at 30, 14, 7, and 1 days before expiry, for the certificate and for the domain registration, using the same UTC day count. A failure alert fires only after 3 consecutive failed checks, and one recovery notice is sent when the incident clears. The same incident is not repeated inside a 24-hour cooldown.

Email. On every plan, including Free, alerts are emailed to the address on your account. Email alerts reach external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested), so check your spam or promotions folder if an alert seems late, and keep the dashboard as your source of truth.

Webhooks, by plan. Solo includes one generic JSON webhook. Agency and Agency+ add a Slack-compatible webhook, which is an incoming-webhook URL you paste, not an installed Slack app. Free has no webhook. Open Webhooks in the dashboard menu to save a URL, send a test, or remove it. Each post is signed with a secret shown on that page. The body Domainvane sends is in webhook payload format, and the rules are in alerts and webhooks.

Plans, caps, and paused hostnames

PlanPriceHostnamesAlertsClient report pages
Free$03Dashboard + emailNone
Solo$9/mo25Dashboard + email + 1 generic JSON webhookNone
Agency$29/mo150Dashboard + email + JSON webhook + Slack-compatible webhookUp to 50
Agency+$79/mo750Dashboard + email + JSON webhook + Slack-compatible webhookUp to 200

Paid checkout is open for Solo, Agency, and Agency+. Webhook URLs are set on the Webhooks page (see Alerts above).

The cap is enforced on the server when you add a hostname. An add that would pass the cap is rejected and no row is created. A bulk paste stops at the cap and marks the rest limit.

A paused hostname stays on the account, counts toward the cap, and is not checked or alerted. Deleting a hostname removes it and frees the slot. Pausing does not free a slot.

If you move to a plan with a smaller cap, nothing is deleted. The newest hostnames over the new cap are paused, and new adds stay blocked while the total (paused names included) is over the cap. Upgrading does not unpause them. You unpause by deleting other hostnames until the total is inside the cap, then unpausing the ones you still want. Those unpause steps are yours; the upgrade does not do them.

Cancellation keeps the paid plan until the end of the current billing period and then returns the account to Free. The rules above are what the product enforces when a plan is set or changed. Enabling a channel or creating a report page your plan does not include returns a forbidden response, and that channel is not contacted.

Share a status page with a client

Read-only client report pages are included on Agency and Agency+ only. Free and Solo do not include them. While signed in on an Agency or Agency+ plan, open Report pages to create a page with a client label and an explicit list of your hostnames. The page lives at /r/<token> on this site. Anyone with the link can view it; the bearer token is not authentication, and you can revoke it. See client report pages.

This version's scope

This version has no public API and no API keys. It has no SMS, no weekly digest, no team seats, and no white-label or custom-domain report pages. The Slack option is a webhook URL, not an installed Slack app.

A one-hostname certificate check is available without an account at /tools/ssl-checker. That check is separate from the hostnames saved on your account.

Delete the account

Account deletion is immediate and cannot be undone from the product. Read account deletion before you use it.