On this page
The regions
| Region | PoP | City | Continent |
|---|---|---|---|
| na | ewr | Newark | North America |
| sa | gru | São Paulo | South America |
| eu | fra | Frankfurt | Europe |
| af | jnb | Johannesburg | Africa |
| as | sgp | Singapore | Asia |
| oce | syd | Sydney | Oceania |
All 6 regions are active. Free uses 2 regions, Pulse 3, and Sentinel and above all 6.
The API, MCP, and the sample SLA report use the region keys above. The product views name the continent.
Regional voting applies to 11 regional check types. Agent and heartbeat monitors use neither probe regions nor regional quorum and follow their own incoming-signal rules instead.
How a check runs
Probe nodes pull their work from the control plane. Every few seconds, each node asks for the checks due in its region, runs them, and reports the full result. A node that goes silent stops taking work and cannot silently drop your checks.
Each node runs its own recursive, validating DNS resolver. DNS results come from the real DNS
tree, not from a public resolver’s cache. Perstat reports dns_ms separately from total latency,
so a slow resolver never looks like a slow application.
Reachability checks can run on IPv4, IPv6, or both, and report one result per IP address. Without a choice, a check uses IPv4. DNS, DNS hygiene, and domain checks run without address families, and traceroute follows a single IP address.
Where a supported probe check emits attribution, the result names one of these layers:
- Your application
- Your DNS
- The network in between
- Our resolver
- Our own probe node
Unknown remains a valid state while attribution is not determined. Not every outcome carries a
cause layer.
How the 11 regional check types vote
For these 11 types, two thresholds sit between a failed check and an alert:
- Within a region. The algorithm folds fresh node results and requires 75% agreement when more than one probe node is active. Today each of the 6 regions has one active node, so this layer is 1/1. It adds no second independent corroboration inside the region.
- Across regions. An incident opens only when a quorum of regions confirms the failure, 2 regions by default. A separate quorum confirms recovery. Results older than the freshness window do not count toward quorum. This is the active cross-region confirmation in the current topology.
Below quorum, Perstat drops nothing silently. A forming incident is visible in the product and names the first failing region.
Sub-quorum divergences, such as one region drifting or one IP family failing, land on a watchlist instead of paging anyone. Node disagreement also appears there when a region has more than one active node. A watchlist entry must last a full check interval before it is reported.
An incident starts at the quorum confirmation, to the second. Your availability record later uses the same boundary.
Customers receive probe egress details on request
Customers who need probe egress details for allowlisting receive them on request. Node IP addresses and hosting providers are not published.
The probe nodes hold no customer account data: they measure and report. The control plane stays in the EU under a German company. The rest of that story is on the security page.
Take the tour, or see the check types the fleet runs.
