Skip to content

Scan is stalled or deferred

A scan that is taking longer than you expected is usually waiting rather than broken. Tidehawk never shows an open-ended spinner: every scan reaches a definite state, and most of the states clear on their own.

Banner What it means What to do
Discovery in progress A scan is running normally Nothing. The page refreshes itself
Certificate lookup temporarily unavailable Public certificate records are unreachable; Tidehawk is retrying Nothing. It says “No action needed”
Discovery is taking longer than usual The scanner is catching up and will resume this shortly Nothing
Discovery paused — service resuming The monitoring service is briefly offline Nothing. It resumes automatically
Discovery failed Every retry was exhausted Select Retry now

Each banner shows a timer counting how long the current wait has run.

Certificate transparency directories are rate-limited. When the hourly allowance for the primary directory is spent, Tidehawk does not fall back to a thinner source and call the job done. It puts the scan back on the queue to run once the allowance refills, and shows Discovery is taking longer than usual while it waits.

That wait can be anything from half a minute to about an hour, depending on when the window refills. You get a complete scan slightly later rather than a partial one straight away. After several such waits Tidehawk stops waiting and runs with whatever sources are available.

Discovery paused — service resuming means the background service that runs scans is not currently reporting in. Tidehawk says so instead of pretending a queued job is progressing. Queued work is not lost; it runs when the service is back.

Discovery is taking longer than usual with no queued job means the scan has been waiting past the point where it should have started. Tidehawk re-queues a stuck scan automatically, up to three times. If all three attempts pass without a result, the domain is marked as a degraded scan so the interface resolves rather than spinning, and the normal six-hourly sweep picks it up again later.

Use Retry now on the Discovery failed banner. That is the one state that will not clear itself.

Otherwise, you can force a fresh scan from any client page with Run Discovery, or Re-scan where certificates already exist. The button becomes Scan queued and the progress banner takes over.

Manual re-scans are rate-limited per workspace. Pressing repeatedly returns “Too many scan requests. Please slow down.” Wait a minute and it clears.

The Domains page shows the state of each domain’s last scan in its Discovery column: Scanning, Failed, No certs, Degraded or Healthy. Selecting a row opens a panel with the last scan time, the scan quality and the failure reason where there is one.

If a domain sits in the same state for more than a day across several six-hourly sweeps, contact support@tidehawk.co with the client name and hostname, or use https://tidehawk.co/contact.