# My site is up but shows down

You open the site yourself and it loads fine, but HostTracker reports it down (or shows a certificate/content
error that doesn't match what you see). The most common cause is that something in front of your site - a web
application firewall (WAF), a bot-defense service, or a CDN's challenge page - is blocking or challenging the
**monitoring checkpoint's** request, while your own browser sails through.

## Why this happens

Automated protection services often treat requests from data-center IP ranges (which is where monitoring
checkpoints run from) with more suspicion than requests from residential or mobile networks. A checkpoint may be:

- Served a **CAPTCHA or JavaScript challenge page** instead of your real content (the check then fails a
  content/status check even though the page "loaded").
- **Blocked outright** by an IP or ASN-range rule, which looks like a connection failure or a `403`.
- **Rate-limited**, which looks intermittent rather than constant.

## How to tell this is what's happening

- Failures cluster on the **same one or two checkpoints** every time, rather than spreading across your
  monitoring locations.
- The check log shows a response that looks like a challenge/CAPTCHA page, or a flat `403`/`406`, rather than a
  real error from your application.
- The failure is consistent and repeatable from those locations, not random.

Open the failed check's details (the snapshot, where available) to compare what the checkpoint actually
received against what your browser sees. Through the API, `GET /monitor/{id}/result/{resultId}/snapshot`
returns that raw captured response for a specific result (the check log gives you the result id); the plain
result read carries the error text and, for HTTP-based types, the status code.

## How to fix it

1. **Allowlist HostTracker's monitoring checkpoints** in your WAF, firewall, or bot-defense rules, so their
   requests skip the challenge. HostTracker's agent addresses are published so you can build this list.
2. If your protection service can allowlist by **user agent** instead of IP, that works too, since checkpoint
   IPs can change over time as the network grows.
3. If you can't or don't want to allowlist globally, you can change which locations a specific monitor uses -
   see [Set your default locations](/monitors/default-locations/) - to avoid the checkpoints your WAF is
   blocking, though allowlisting is the more durable fix.

## Related

- [How down detection works](/monitors/down-detection/)
- [Common check errors and what they mean](/troubleshooting/common-errors/)
- [Set your default locations](/monitors/default-locations/)
