# Website checks

Entering your website address is the zero-install first connection. Xovris checks the site from outside, the way your
customers reach it, before you install anything or connect any account. The same check answers a plain request with no
account. To count free checks it keeps only keyed hashes of your IP address and of each website, never the readable
address, for 25 hours:

<PageTask next={{ label: 'Check your website now', href: '/#start' }}>
  <SnippetCode kind="public-check" />
</PageTask>

## What is checked

- **The page**: the address answers over HTTPS, with its status and how long it took.
- **The certificate**: it is valid for the name, trusted, and how long it has left.
- **DNS**: the name resolves, and to which addresses.
- **The domain's registration**: its registrar and when it expires, from the registry's own records (RDAP).

Each result appears on your Overview as soon as it is stored. Nothing is shown before its record exists.

## What you can enter

Type the address the way you would in a browser – `shop.example.com` or a full address with a path both work. Xovris
adds `https://` when you leave it out.

## Addresses Xovris refuses, and why

Xovris only checks what a public check can reach, and it says why when it refuses:

| You entered | What happens |
|---|---|
| An address on a private network (for example a `10.x` or `192.168.x` address) | Refused for safety: the public check reaches only public addresses. Enter the address your customers use. |
| A name that only works inside your network (`.local`, `.internal`, `localhost`) | Refused, for the same reason. |
| A username or password inside the address | Refused: Xovris never stores credentials in a URL. |
| A port other than 80, 443, 8080 or 8443 | Refused: use the standard address. |
| Anything that is not `http` or `https` | Refused: only web addresses can be checked. |

## Next

[Connect your app](/docs/) to see errors from inside it, or read [the verification ladder](/docs/start/verification-ladder/).
