What the checker tries, in order
Each step needs the one before it, so the first step that fails is usually the cause. Fix that one and run the check again.
- DNS lookup: does the name resolve to an IP address? No answer usually means the domain expired, the nameservers were changed, or the A record was deleted.
- Connection to port 443: does the server accept a connection? A timeout tends to mean a firewall or a server that's off; a refused connection means the machine is up but nothing is listening on that port.
- TLS handshake: does the server present a certificate a browser accepts for this name?
- https:// and http://: the status code the homepage returns, where its redirects end and how long the answer took.
How to read the verdict
Up means the homepage answered with a 2xx status, directly or after redirects. Down means there was no usable answer: the name didn't resolve, the connection timed out or was refused, or the server returned a 5xx error. The middle case, answers but not normally, covers a 4xx error, a broken certificate while http:// still works, and a bot challenge page.
A challenge page (the "Just a moment..." screen and similar) means the site is up for people but a firewall stopped an automated request. Google's crawlers can be stopped the same way. AdSense's help lists "Your site is unreachable" as one reason a site isn't ready to show ads, so if you see a challenge here, test Google's crawlers with the Googlebot access checker as well.
Google's crawlers slow down when a site returns 5xx or 429 errors, and treat other 4xx codes as content that doesn't exist, according to Google's crawling documentation. A short outage costs little; days of errors are what hurt.
Cloudflare errors 520 to 526
When the site is behind Cloudflare, a 52x code means Cloudflare itself answered but couldn't get a good response from your server (the origin). Cloudflare's own names for them:
- 520 Web server returns an unknown error
- 521 Web server is down
- 522 Connection timed out. Cloudflare says the most common cause is its IP addresses being rate limited or blocked by the origin's firewall, .htaccess or iptables.
- 523 Origin is unreachable
- 524 A timeout occurred
- 525 SSL handshake failed
- 526 Invalid SSL certificate
Down for everyone, or just you?
We check from one place: our server. If we reach the site and you can't, the problem is probably between you and the site: your DNS cache, your network or VPN, or a firewall that blocked your IP address. If we can't reach it either, it's very likely down for others too, but one location can't prove that for every country or network.
To find out when it goes down, rather than checking by hand, monitoring watches it for you and emails you.