# Website checks

A website check requests a URL on a schedule and alerts when the URL stops working, or answers with a status code you don't expect.

:::tip[New to Uptime?]
Start with [Get started with Uptime](/docs/uptime/).
:::

## Adding a website check

In **Add check**, choose one of these under **Alert us when…**, then enter the **URL to monitor**. If you leave out `http://` or `https://`, `https://` is added.

| Alert us when… | Down when |
| --- | --- |
| URL becomes unavailable | Any of the failures listed below. |
| URL returns HTTP status other than | The response's status code isn't one you list. |

For **URL returns HTTP status other than**, fill in **Expected HTTP status codes** with codes or ranges, such as `200-299, 301`. TunnelHQ alerts on any other code.

To add many URLs at once, use [Bulk import](/docs/uptime/#adding-many-checks-at-once).

## When a website check is down

With **URL becomes unavailable**, a check is down when:

- There's no answer: the connection is refused or reset, DNS fails, or nothing arrives within the request timeout.
- The status is outside 200–299. With **Follow redirects** on, it's judged after up to 10 redirects. With it off, the redirect itself is judged, so a redirect counts as down.
- The certificate is invalid, expired, or self-signed, while **SSL/TLS verification** is on.
- The response body is over 10 MB.
- The host has no address of the chosen [IP version](/docs/uptime/checks/#ip-version), such as "ipv4.google.com has no IPv6 address".
- A redirect points to a private or reserved address.

## Request settings

| Setting | Options |
| --- | --- |
| Request method | `GET` (the default), `HEAD`, `POST`, `PUT`, `PATCH`, `DELETE`, or `OPTIONS`. |
| Body | Sent only with `POST`, `PUT`, `PATCH`, and `DELETE`. **JSON** (sent as `application/json`; must be valid JSON), **Form** (`name=value&other=2`), or **XML** (sent as `text/xml`). |
| Headers | Name and value pairs, sent with every check. |
| Basic auth | **Basic auth username** and **Password**. Leave both empty for none. |

Headers, the body, and basic auth are shown only to people whose role can edit monitors. Everyone else sees that the check has request secrets, but not their values.

## Redirects, TLS, and expiration

- **Follow redirects** is on by default and follows up to 10 redirects.
- **SSL/TLS verification** is on by default and treats an invalid, expired, or self-signed certificate as down.
- **SSL expiration** alerts before the site's certificate expires. New checks with an `https://` address start at **Alert 14 days before**.
- **Domain expiration** alerts before the domain's registration expires. It's off by default.

An expiring certificate or domain opens an **Expiring** incident that closes by itself on renewal. See [SSL and domain expiration](/docs/uptime/checks/#ssl-and-domain-expiration).

Check frequency, the confirmation period, and the request timeout are described in [Working with checks](/docs/uptime/checks/#settings).
