Some outages announce themselves.
Slowdowns before a provider admits a problem. Certificates and domains with a known expiry date. Vendors quietly moving their infrastructure. We watch all of it, and we publish how often our warnings were right.
Early warnings
Rule ew-v2: a warning fires when at least 4 independent organisations, and 30% of a provider, region, CDN or DNS group of 8+ organisations with history, run at 2.5× their own 24-hour median latency (and +400 ms) or start failing; the slow services are re-measured immediately, and the condition must hold in two consecutive sweeps. It counts as confirmed if a provider incident opens on the same group within 30 minutes. Scoring is automatic; nothing is edited by hand.
Certificates
We read the TLS certificate of every monitored endpoint daily (— certificates). Auto-renewing authorities (Let's Encrypt, Google, Amazon, Cloudflare) renew about 30 days before expiry, so under 14 days left on such a certificate means renewal is overdue and probably failing.
Domains
Registration expiry from the registries' official RDAP records (— domains). Some registries (for example .io, .de, .at) do not publish RDAP; we report them as unavailable rather than guess. Large companies usually auto-renew; the risk is a domain inside its last two weeks that has not been renewed.
Infrastructure changes
Recorded when a re-mapping finds a different hosting provider, region, CDN, DNS or email provider than before. Migrations are when outages are most likely; a change is a reason to watch, not proof of a problem.