Follow incidents and DNS history
Failure confirmation, recovery, acknowledgement and retained evidence.
A failure and an incident are different
One failed check is an observation. An incident opens after the configured number of consecutive failures. Recovery is confirmed only after the configured number of consecutive successes. A failure resets recovery progress; a success resets failure confirmation.
Example: with three failure confirmations, two failures followed by a successful check do not open an incident. With two recovery confirmations, one success during an incident is not enough to confirm recovery.
Acknowledgement does not fix DNS
Acknowledging an incident records that someone has seen it. It does not change the DNS rule, repair provider records or declare recovery. Follow the current evidence and let subsequent checks confirm recovery.
A monitor can show a successful latest check while an incident is still waiting for its recovery threshold. A domain can also remain unhealthy because another active monitor is failing. Review all active monitors and open incidents for that domain.
Use the timeline
The domain History tab and monitor DNS timeline show confirmed changes, first failure detection, incident confirmation and recovery. Expand an event to inspect the before/after data and relevant source. A change during an incident is a time correlation, not proof that the change caused it.
Individual checks follow the organization's retention setting, initially 30 days. Confirmed changes and incidents have no time-based expiry and remain until their monitor, domain or organization is deleted. The monitor lists the latest 100 retained checks; use history for the broader event sequence.
Documentation reviewed: 8 October 2026. Results describe configured checks and available evidence, not a complete security or service-availability guarantee.
Troubleshooting and contacting Support