Firewall and network requirements
Endpoint checks reach your websites and servers from a fixed set of IP addresses. You can always look up the current list through one DNS name, monitor.doublecheck.live, and allow those addresses in your firewall.
Look up the monitoring addresses
The DNS name monitor.doublecheck.live returns every address a check can come from. Look it up with any DNS tool:
nslookup monitor.doublecheck.live
# Linux / macOS
dig +short A monitor.doublecheck.live
# PowerShell
Resolve-DnsName monitor.doublecheck.live -Type A
Allow all addresses it returns, not only the first. A check can run from any of them.
What to allow per check
Only allow traffic from the monitoring addresses, and only for the checks you use.
- DNS A record monitoring
- Nothing to open. The name is looked up through DoubleCheck's own DNS resolver; there is no connection to your server.
- Ping monitoring
- ICMP echo request (type 8) in, echo reply (type 0) out.
- SSL certificate expiry monitoring
- TCP 443, or the port you set on the check.
- TCP port monitoring
- The TCP port you set on the check.
- TLS version monitoring
- TCP 443, or the port you set on the check.
- Website uptime and HTTP monitoring
- TCP 443 for https, TCP 80 for http, or the port in your URL. If your URL redirects to another host, that host needs the same.
Microsoft 365 and Azure checks
Cloud checks do not connect to your network at all. They read data from Microsoft's APIs with the app registration you create in your own tenant, with read-only permissions. There is nothing to open in your firewall for them.
Web application firewalls and bot protection
A WAF, CDN or bot protection service may block or challenge requests from addresses it does not know. The HTTP check then sees a 403 or a challenge page instead of your site. Add the monitoring addresses to the allow list of that service as well, so the check measures your site and not the protection in front of it.
Frequently asked questions
Why does my check show 403 Forbidden?
A firewall, WAF or bot protection is probably blocking or challenging the monitoring addresses. Add the addresses of monitor.doublecheck.live to its allow list. DoubleCheck reports 403 as a warning, not an error, because the site itself answered.
Can I allow DoubleCheck by user agent instead of IP address?
No. The HTTP check sends a normal browser user agent, so it cannot be told apart that way. Use the IP addresses.
Do the addresses change?
They can. The DNS name always returns the current set, so look it up again whenever you update your firewall rules, or let your firewall resolve the name itself if it supports that.
Is IPv6 used?
At the moment the monitoring addresses are IPv4 only. Check for AAAA records on monitor.doublecheck.live to see whether that has changed.
Do I need to open anything for the Microsoft 365 and Azure checks?
No. Cloud checks never connect to your network. They read data from Microsoft's APIs with the app registration you created.