Domainvane FAQ

Public answers for this site. Limits match the spec. Mail support@domainvane.com if the answer does not cover your case. Pricing detail, including refunds, taxes, and annual billing, lives on pricing.

What is Domainvane?

Domainvane monitors TLS certificates and domain-registration expiry for the hostnames you add and shows results on the dashboard. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested). Agencies and MSPs are the primary users. Solo developers use the same product.

It checks port 443 only. It does not change your DNS, your certificate authority, or your registrar.

Does Domainvane renew certificates or domains?

No. Domainvane shows alert state on the dashboard; email alerts are delivered to external inboxes, including Gmail (inbox placement not guaranteed for every provider). Your CA renews the certificate and your registrar renews the domain. Alert state is a reminder and status, not an automatic renewal.

Who is it for?

Web, marketing, and development agencies, and MSPs, that manage many client hostnames and need one list with alerts. Solo developers and small in-house teams with more than a handful of names are the secondary audience.

One account is one login. Team seats and multi-user organizations are not available. Passwords must be 10 to 128 characters. The account stores a scrypt hash of the password, with a per-user salt.

When do alerts send?

For both the certificate and the domain registration, Domainvane shows dashboard alert state at 30, 14, 7, and 1 days before expiry. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested). The day count is evaluated in UTC from the expiry time on the certificate or the RDAP record.

Separate dashboard failure state appears only after 3 consecutive failed checks, and recovery state appears when the incident clears. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested). Webhook alerts are included on paid plans.

Today alert state appears on the dashboard. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested). Solo, Agency, and Agency+ are available with paid checkout. Those plans add generic JSON and Slack-compatible webhooks according to the pricing table.

How often does Domainvane check?

About every 24 hours for a healthy hostname, plus up to 60 minutes of jitter so checks do not all fire at once. About every 6 hours, plus up to 15 minutes of jitter, when the certificate has 7 days or fewer left or the hostname already has a failed check in a row.

The schedule is the same on Free, Solo, Agency, and Agency+. Checks are periodic. The alert for a threshold goes out on the check that observes it.

What does a TLS check look at?

Domainvane connects to the hostname on port 443 with that hostname as SNI. It records whether the certificate is not yet valid or expired, days until notAfter, whether the hostname matches a subject name or SAN (a wildcard matches one label and does not match the bare parent), whether the chain completes against Node's default CA store, and whether the certificate is self-signed.

Stored fields are the normalized result: fingerprint, dates, issuer, subject, match and chain flags, and an error code. The raw certificate chain is not stored.

What do the status codes mean?

The first matching status is the one you see, in this order:

StatusMeaning
DNS_FAILThe name did not resolve.
CONN_REFUSEDThe connection to port 443 was refused.
TIMEOUTThe connect, handshake, or lookup timed out.
TLS_PROTOCOLThe TLS handshake failed.
NOT_YET_VALIDThe certificate's start time is still in the future.
EXPIREDThe certificate's end time has passed.
SELF_SIGNEDThe certificate is self-signed.
CHAIN_INCOMPLETEThe chain did not validate against Node's default CA store.
HOSTNAME_MISMATCHThe certificate is not valid for that hostname.

Those nine codes are the TLS check taxonomy. Separately, a hostname that resolves to a non-public address is not connected to. The public checker reports that case as blocked. It is not one of the nine codes above.

Why does domain expiry say "unknown"?

Domain expiry comes from RDAP only. Domainvane shows a date when the RDAP record has one. It shows unknown when the TLD is not supported, the lookup has no usable HTTPS RDAP base, the expiry is missing, or the data is ambiguous. It does not guess, and it does not fill the gap from somewhere else.

Common gTLDs that publish HTTPS RDAP are in scope. Other TLDs show unknown. A timeout, a rate limit, or a malformed RDAP response is stored as an error, not as a date.

What does registry vs registrar mean?

When RDAP provides an expiry, Domainvane also stores where that event came from: registry or registrar, and which RDAP server answered. Those two sources can disagree with each other, and either can disagree with the date on your registrar's renewal screen. Domainvane shows the provenance so you can see which one you are looking at. It does not claim that the date is the registrar's billing renewal date.

Do you use WHOIS?

Domainvane uses RDAP over HTTPS. It does not scrape WHOIS and it does not open port 43.

How do I add a lot of domains?

Paste a list separated by newlines, commas, or spaces. You get a result for each entry:

  • added — saved on your account
  • duplicate — you already monitor that hostname and port
  • invalid — empty, spaces, characters that are not a hostname, a bare IP, or an over-long label
  • limit — saving it would pass your plan cap, so it was not saved

Invalid rows are not added. The paste stops adding once the cap is reached. The same hostname is not stored twice for one account.

The public page at /tools/bulk-ssl-checker is an explanation and a link to signup. It does not run a bulk check. Bulk monitoring runs on the hostnames saved in the account. The one-hostname checker is separate: POST /public/check, also linked from /tools/ssl-checker.

What is a client report page?

Client report pages are included on Agency and Agency+. The limits are 50 pages on Agency and 200 on Agency+. You create a page on the Report pages screen with a client label and a list of hostnames you already monitor. Anyone with its link can view the read-only status without a login.

The link contains a long random token that Domainvane stores only as a hash. A revoked link and an unknown link both return the same 404. If you move to a plan without report pages, existing links keep working until you revoke them on the Report pages screen, and you cannot create new ones.

Report-page URLs need to be treated as secrets. Custom domains, your logo, and white-label styling are not available. Agency and Agency+ include client report pages.

What does the free public checker store?

POST /public/check tests one hostname on port 443. No login. The hostname you submit is not stored. The analytics row for that check records only whether the result was ok, error, or blocked.

It is rate-limited in memory: 20 checks per IP address every 10 minutes (IPv6 addresses count per /64), and at most 1,500 new checks per hour across all visitors. A result for the same hostname is reused for 5 minutes (1 minute after a connection error), and a reused result does not count toward the hourly cap. At most 8 checks are admitted at once, with up to 32 more waiting; beyond that the checker answers that it is busy. The checker waits at most 10 seconds for a host and then reports a timeout. The public checker has its own limits and does not draw on the outbound budget used for scheduled account checks. Over a limit, the response is 429 with a Retry-After header. Names that resolve to non-public addresses are blocked and are not connected to.

/tools/ssl-checker is the form for this checker; each submission is one check under the limits above. It judges only the certificate chain the server sends and does not download missing intermediates, so a missing intermediate shows as CHAIN_INCOMPLETE. /tools/domain-expiry-checker and /tools/bulk-ssl-checker are explanation pages with a link to signup. They do not run checks.

What are the plans?

PlanPriceDomainsChannelsReport pages
Free$03Dashboard now; email alerts including GmailNone
Solo$9/mo25Email alerts (including Gmail) + 1 JSON webhookNone
Agency$29/mo150Email alerts (including Gmail) + JSON webhook + Slack-compatible webhookUp to 50
Agency+$79/mo750Email alerts (including Gmail) + JSON webhook + Slack-compatible webhookUp to 200

Paused domains count toward the cap. Full comparison, cancellation, downgrades, refunds, taxes, and annual billing: pricing.

Refunds are not offered unless a policy is published or the law requires one. The pricing page does not state a tax treatment. Annual billing is not offered. Solo, Agency, and Agency+ are available to purchase. Start free.

What happens if I downgrade or pause a domain?

You can pause a hostname. It stays on the account, counts toward the cap, and is not checked or alerted.

If you change to a plan with a lower cap, the change applies immediately. Hostnames are not deleted. The newest hostnames over the new cap are paused, and new adds are blocked while the total, paused hostnames included, is over the cap. They stay paused until you unpause them. Upgrading does not unpause them. Getting under the cap means deleting hostnames. Pausing does not free a slot, because paused hostnames still count.

Cancellation is not immediate. See the next answer.

What happens if I cancel?

Cancellation keeps the paid plan through the end of the current billing period and then returns the account to Free. Paid checkout is open. The current Free experience covers 3 domains and dashboard status; email alerts are delivered to external inboxes, including Gmail. Hostnames over 3 are not deleted; the newest ones over the cap are paused. Report pages are not revoked; their links keep working until you revoke them.

How do I delete my account, and what is left?

Delete the account in settings while you are signed in. That is how an account is deleted. Deletion is a hard delete in one transaction. It removes the user, sessions, notification settings, report pages, billing rows, that address's email-outbox rows, that account's rate-limit buckets, and the domains plus their TLS results, RDAP results, alerts, and notification rows. There is no "deleted" flag and no undelete.

Email to support does not delete the account. Support deletes an account only after the account holder confirms the deletion inside a signed-in session. A message's From address is not that confirmation. If you cannot sign in, this version does not delete the account from email.

Analytics rows are kept and are de-linked from your account; they contain no email, hostname or token.

Local backup copies can still contain the deleted rows until those backup files age out (BACKUP_RETENTION_DAYS; the example configuration uses 14 days). Domainvane does not offer instant removal from existing backups.

Do you verify that I control a domain?

This version does not ask you to prove control with a DNS record or a file on the site. You must only add hostnames you are allowed to monitor. Domainvane will connect to port 443 and send the name to the relevant RDAP service. Bare IP addresses are rejected as targets. Names that resolve only to non-public addresses are blocked.

Are team logins, SMS, an API, or white-label reports included?

No. SMS, a weekly digest, team seats, a public API or API keys, and WHOIS are not available. White-label and custom-domain report pages are roadmap, not part of this version. A Slack-compatible webhook is included on Agency and Agency+; a Slack app install is not planned.

Why are shorter certificate lifetimes relevant?

More renewals mean more chances to miss one. CA/Browser Forum Ballot SC-081v3 limits a publicly trusted subscriber certificate to a maximum validity of 200 days when issued on or after 15 March 2026, 100 days when issued on or after 15 March 2027, and 47 days when issued on or after 15 March 2029 (Baseline Requirements section 6.3.2). Source, checked 2026-09-25: https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/ and https://github.com/cabforum/servercert/blob/Reduce-Max-Validity-and-Data-Reuse-Periods-Over-Time/docs/BR.md. Domainvane shows dashboard alert state at 30, 14, 7, and 1 days; email alerts are delivered to external inboxes, including Gmail (inbox placement not guaranteed for every provider).