# Requests from StatusTick

> Why your server sees requests with the StatusTick User-Agent, how to recognise them and how to let them through a firewall, WAF or bot protection.

You are probably here because your logs show requests with this User-Agent:

```
StatusTick/2.0 (+https://statustick.com/docs/checks)
```

StatusTick is an uptime monitoring service. Someone, usually a person on your own team or a company that depends on your service, has set up a monitor for one of your addresses. StatusTick then requests that address at a regular interval, from several regions, to see whether it answers and how fast.

The requests are monitoring checks. They do not crawl your site or follow its links.

## How to allow the checks

If a firewall, a WAF or bot protection blocks or challenges these requests, the monitor shows **Blocked** and its owner cannot see the real status. There are three ways to let the checks through:

1. **User-Agent.** Allow requests whose `User-Agent` is `StatusTick/2.0 (+https://statustick.com/docs/checks)`. This is the simplest rule, but anyone can send the same value, and it covers HTTP checks only. Browser checks load the page in Chromium and look like a normal Chromium visit, so for them use the IP addresses.
2. **IP addresses.** Allow the IPv4 and IPv6 addresses the checks come from. This covers every check type. The list is public and machine-readable:

   ```
   https://api.statustick.com/v1/drone-ips
   ```

3. **A custom header.** The monitor's owner can add a request header with a secret value to the monitor, and you allow requests that carry it. This is the strictest rule.

[Allowlisting StatusTick](https://statustick.com/docs/allowlisting-statustick) has the details for each option and explains what Blocked means.
