On this page
Incidents & alerts
How incidents work
DomainDash catches problems and confirms they're real before it tells you, so you hear about what matters, and nothing slips through.
What is an incident in DomainDash?
An incident is a record of something going wrong with one of your sites. When DomainDash spots a problem (your site going Down, an SSL certificate expiring, or DNS failing) it opens an incident for you automatically. When the problem clears, the incident resolves itself too. There's nothing for you to open or close by hand; DomainDash handles the whole lifecycle, so you can step in only when there's something to actually fix.
If you've got an active SSL incident and want to know what's causing it, jump to the SSL troubleshooting section for specific causes and step-by-step fixes. Troubleshooting guides for uptime, DNS, and domain registration live under the Troubleshooting section too.
Detection runs on every plan; the incidents experience is a feature
DomainDash detects problems and emails your team when a site goes Down on every plan, including Free. The full incidents experience (timelines, team updates, live check status, and postmortems) is part of the Incidents feature.
Plan availability
Incidents is available on Pro and Business. See the plan comparison.
Detection
DomainDash doesn't raise the alarm after a single failed check. Networks are noisy, and a one-off timeout doesn't mean your site is Down. Instead, we use a confirmation process to make sure a problem is real before we tell you about it, so when an alert does land, you can trust it's worth acting on.
Here's what happens:
- A check comes back with a problem (for example, your site returns an error or doesn't respond at all).
- DomainDash creates an incident in a confirming state and starts counting.
- We keep checking. Each time the same problem comes back, the confirmation count goes up.
- Once enough consecutive checks confirm the problem, the incident is opened and you get notified.
The number of confirmations required depends on the severity of the problem. Urgent problems like a site going Down need fewer confirmations (so you hear about them faster), while less urgent things like a certificate approaching expiry need a few more checks to rule out false positives.
If the problem goes away before enough confirmations are reached, the incident is quietly discarded. You never even see it: no false alarm, no 3am text over a blip that fixed itself.
Severity
Not all problems are equally urgent, and you shouldn't be pulled away from your day for something that can wait. DomainDash gives each incident a severity level based on what's gone wrong, so the urgent stuff stands out and the rest waits its turn. The scale runs from P0 (most urgent) to P3 (least urgent):
| Severity | Label | What triggers it |
|---|---|---|
| P0 | Urgent | Your site is Down, or a page failed its content check |
| P1 | Needs fixing | Your SSL certificate or domain name has expired, your SSL certificate is invalid, or DNS resolution is failing |
| P2 | Needs a look | Your site is responding slowly |
| P3 | Worth knowing | Your SSL certificate or domain name is expiring soon (this rises to P2 in the final day before the deadline) |
In the app, severity appears as the bare code (P0, P1, P2, P3) alongside the problem. The friendly labels above are how we talk about each level.
Severity affects two things:
- How quickly you're notified. P0 incidents trigger an urgent email to every member of your team who hasn't opted out of incident alerts, within about a minute of being confirmed. Lower-severity incidents are grouped into a daily digest instead.
- How many confirmations are needed. This depends on the kind of problem, not its severity. A Down site, a failed content check, an invalid certificate, or failing DNS takes 2 checks to confirm. A slow site is the most patient case. It has to stay slow for around a dozen checks before we flag it, so a brief wobble won't bother you. Anything to do with expiry, whether a deadline is approaching or has passed, opens on the very first check, because the date is certain and there's nothing to rule out.
What types of incident can be raised?
DomainDash checks four aspects of your site and can raise incidents for each:
| Check type | Possible incidents |
|---|---|
| Uptime | Site is Down, site responding slowly, page failed its content check |
| SSL certificate | Certificate expired, certificate problem, certificate expiring soon |
| DNS | Domain routing is failing |
| Domain registration | Domain expired, domain expiring soon |
A failed content check (when a page loads but doesn't contain the text, element, or JSON response you asked us to look for) is part of content checks and raises a P0 incident. Each incident type is tracked independently, so if your site goes Down and your SSL certificate expires at the same time, you'll see two separate incidents, one for each problem.
Recovery and resolution
When the underlying problem goes away, DomainDash doesn't rush to declare the incident over. It confirms the recovery is genuine first, so you don't get a premature "all clear" while a site is still flickering between up and down — and when you do hear it's fixed, you can believe it.
Here's what happens when checks start passing again:
- The incident enters a recovering state. DomainDash has detected that things look better, but wants to make sure.
- Additional checks are run to confirm the recovery. Each consecutive healthy check builds confidence that the problem is genuinely resolved.
- Once enough consecutive healthy checks pass, the incident is marked as resolved with a timestamp.
- For P0 (Urgent) incidents, a resolved notification is sent to your team so everyone knows the problem is over.
If a check fails during recovery, the incident goes straight back to open. This means DomainDash won't tell you something is fixed until it's confident the fix is stable.
Incidents that were still in the confirming stage (not yet opened) are resolved silently. Since you were never notified about them, there's nothing to follow up on.
You can't manually close incidents
Incidents are tied to real check data, so they're only resolved when DomainDash confirms the problem is gone. This keeps your incident history accurate and trustworthy. Every open incident genuinely represents an ongoing problem.
Frequently asked questions
What's the difference between P0, P1, P2, and P3 incidents?
Severity levels describe how urgent an incident is. P0 (Urgent) means your site is Down, or a page failed its content check. P1 (Needs fixing) means your SSL certificate or domain name has expired, your SSL certificate is invalid, or DNS resolution is failing. P2 (Needs a look) means your site is responding slowly. P3 (Worth knowing) means your SSL certificate or domain name is expiring soon. P0 triggers urgent alerts; P1–P3 are grouped into the daily digest.
How long does it take for an incident to be confirmed?
It depends on the kind of problem and your check frequency. A Down site, a failed content check, an invalid SSL certificate, or failing DNS is confirmed after 2 consecutive checks. A slow site is treated more patiently. It has to stay slow for around a dozen checks before it's flagged, so a brief wobble won't bother you. Anything to do with expiry, whether a deadline is approaching or has already passed, opens on the very first check. With a 1-minute check frequency, a Down site is typically confirmed within 2–3 minutes of going offline.
Can I manually close an incident?
No. Incidents are tied to real check data, so they only resolve when DomainDash confirms the problem is gone through consecutive healthy checks. This keeps your incident history accurate: every open incident represents an ongoing problem, not a forgotten ticket.
What happens to incidents during recovery?
When checks start passing again, the incident enters a "recovering" state while DomainDash runs additional checks to confirm the recovery is genuine. If a check fails during recovery, the incident goes straight back to "open". This prevents false "all clear" notifications during unstable incidents where the site flickers between up and down.
Will I be notified for every incident?
Only P0 (Urgent) incidents trigger urgent alerts within about a minute of confirmation. P1, P2, and P3 incidents are grouped into a daily digest email so you're not interrupted for non-urgent problems. This keeps notifications meaningful and avoids alert fatigue.
Related
- Incident detail page to see the full timeline and post updates during an incident
- Notification channels to choose how you're alerted when something goes wrong
- Incident history to browse and filter all incidents across your sites
- Uptime checks for how DomainDash checks whether your site is online
Start checking your sites for free
DomainDash keeps an eye on your uptime, SSL, DNS, and domain registration so you don't have to — and tells you the moment something needs your attention. Set up in under a minute, no credit card.
Last updated: 19 June 2026