Something isn't loading. Is the site actually down, or is it your connection? Is the API returning errors, or is your client misconfigured?
Before you start debugging your own setup, verify the problem with an independent check.
Quick Answer: Run an Independent Check
Which tool you reach for depends on what you are checking.
For a website, use the free website uptime checker. Paste the address and it runs a deep check in one pass — whether the site answers at all, plus DNS, SSL, security headers, TTFB and content health, each graded so you can see which layer is broken rather than just "up" or "down".
For an API endpoint, use the free API status checker. Enter the address and get:
- HTTP status code (200, 301, 403, 500, etc.)
- Response time in milliseconds
- Security headers audit
- CORS configuration check
- Redirect chain analysis
Either way the read is the same: a 200 with a fast response time means the site is up and the problem is on your end. A 5xx or a timeout means it is genuinely down.
Understanding HTTP Status Codes
The status code tells you exactly what's happening:
Success (2xx)
- 200 OK: Everything works. The server responded successfully.
- 201 Created: The resource was created (common for POST requests).
- 204 No Content: Success, but nothing to return (common for DELETE requests).
Redirects (3xx)
- 301 Moved Permanently: The URL has permanently moved. Update your bookmarks.
- 302 Found: Temporary redirect. The original URL is still valid.
- 307/308: Temporary/permanent redirect preserving the HTTP method.
A single 3xx tells you little on its own — what matters is where the chain ends. Use the redirect checker to trace every hop from the original URL to the final destination and spot loops or chains that quietly cost you response time.
Client Errors (4xx)
- 400 Bad Request: Your request is malformed.
- 401 Unauthorized: Authentication required.
- 403 Forbidden: You don't have permission.
- 404 Not Found: The page doesn't exist.
- 429 Too Many Requests: You've been rate-limited.
Server Errors (5xx)
- 500 Internal Server Error: Something broke on the server.
- 502 Bad Gateway: A proxy or load balancer can't reach the backend.
- 503 Service Unavailable: The server is overloaded or in maintenance.
- 504 Gateway Timeout: The backend didn't respond in time.
The API status checker shows you which code the server returns, so you can quickly determine whether the problem is client-side or server-side.
Checking Website Status Step by Step
Step 1: Check from an independent source
Don't rely on your own browser. Your local DNS cache, corporate proxy, or ISP could be the problem. Run the website uptime checker to test from an external location — if it reports the site online while your browser doesn't, the fault is local to you.
Step 2: Check DNS resolution
If the status checker can't reach the site at all, DNS might be the issue. Run:
nslookup example.com
dig example.comIf DNS isn't resolving, check with the domain expiration checker — the domain might have expired.
Step 3: Test connectivity
Use the free ping test to check if the server is reachable at the network level. If ping succeeds but HTTP fails, the problem is the application, not the network.
Step 4: Check SSL
If the site loads over HTTP but not HTTPS, the SSL certificate might be the issue. Run the SSL checker to verify certificate validity.
Checking API Endpoint Health
APIs require more thorough checking than websites because failures are often partial — some endpoints work while others don't.
What to verify
- Status code: Is the API returning 200 or an error?
- Response time: Is it responding within acceptable latency?
- Response body: Is the API returning valid data or error messages?
- Security headers: Are CORS, CSP, and other security headers properly configured?
- Redirect chain: Is the API redirecting requests unexpectedly?
The API status checker tests all of these in a single scan.
Testing authenticated endpoints
For endpoints that require authentication, you'll need to use curl or Postman:
curl -I -H "Authorization: Bearer YOUR_TOKEN" https://api.example.com/v1/healthFor public health check endpoints, the free status checker works perfectly.
Security Headers: Why They Matter
The API status checker also audits your security headers. Here's what to look for:
- Strict-Transport-Security (HSTS): Forces HTTPS connections
- Content-Security-Policy (CSP): Prevents XSS attacks
- X-Content-Type-Options: Prevents MIME sniffing
- X-Frame-Options: Prevents clickjacking
- Referrer-Policy: Controls referrer information leakage
Missing security headers don't cause downtime, but they leave your site vulnerable to attacks that eventually will.
When It's Down: Immediate Actions
If you've confirmed the site is genuinely down:
- Check your hosting provider's status page for known incidents
- Check server logs for error messages
- Restart services if you have server access
- Check recent deployments — a bad deploy is the most common cause
- Monitor DNS and SSL — sometimes the website is fine but DNS or certificates are broken
Setting Up Proactive Monitoring
Checking whether a site is down after users complain is reactive. Setting up monitoring so you know before users do is proactive.
Exit1.dev monitors your endpoints continuously:
- HTTP, HTTPS, API, and ICMP checks from multiple global regions
- Response time tracking with historical data
- Security header auditing
- SSL certificate monitoring
- Multi-channel alerts via email, Slack, Discord, webhooks, and SMS
Start with a quick check using the API status checker, then set up continuous monitoring at exit1.dev for free.
Recommended Resources
- Free Website Uptime Checker – Is the site online and healthy? Graded checks across DNS, SSL, security, performance, and content
- Free API Status Checker – Check any URL's status, response time, and security headers
- Free Redirect Checker – Trace the full 301/302/307/308 chain hop by hop
- Free Ping Test – Test network connectivity and latency
- Free SSL Checker – Verify SSL certificate validity
- Free Domain Expiration Checker – Make sure your domain hasn't expired
- API Endpoint Monitoring Playbook 2025 – Build a comprehensive API monitoring strategy