DocsYour apps

Alerts

Where alerts go, who can change that, and what each email means.

Needs an accountUpdated
On this page

In short

  • Alerts are emails about your apps. They go to one main address and up to four more, set under Alerts in the company settings. Your first company starts with the address you signed up with, whatever name you give the company when you start.
  • Three switches choose what reaches you: an app stops answering, something new and serious turns up, and a finding is confirmed fixed. All three are on by default, and one switch above them turns every alert email off.
  • Only an admin changes any of it; a member reads a sentence that says so. Incident emails need a paid plan. The emails about new or fixed findings go out on every plan.

Where in the app

Alerts is a section of the company settings. Click the row with your name at the foot of the sidebar, click Settings, then click Alerts under Company in the list beside the page. On a phone, the list is a row you can swipe sideways. Your company shows the menu and the list.

The Alerts section of the company settings with the Where alerts go card ringed: the Send alerts by email switch, the address fields and Save addresses. The What reaches you card with its three switches follows it.

Step by step

The Alerts section: the Where alerts go card (1) with the Where to send it field (3), the Also send to field (4) and the Save addresses button (5), and the What reaches you card (6) with the From which severity choice (7).
  1. Open Alerts

    Open Settings from the account menu, then click Alerts under Company. While alerts reach nobody, a dot sits beside Alerts in the list.

  2. Switch email alerts on

    Turn on Send alerts by email. With it off, Vallit sends nothing, whatever is chosen below. Once an address is saved, the switch saves the moment you flip it.

  3. Enter the main address

    Type the address into Where to send it. A shared inbox works, so more than one person sees each alert. The address is used for nothing else.

  4. Add more addresses

    Under Also send to, type up to four more addresses, one per line. They get the same messages at the same moment. An address that is also the main address is not sent twice.

  5. Save the addresses

    Click Save addresses. The button reads Saving, then a message confirms it: Saved, followed by where the alerts now go. Until you save, the form reads Not in effect yet.

  6. Choose what reaches you

    Under What reaches you, switch An app stops answering, Something new and serious turns up and A finding is confirmed fixed on or off. Each saves the moment you flip it, and a message says Saved.

  7. Pick a severity

    While Something new and serious turns up is on, From which severity offers Critical, High and Medium. The choice saves at once.

What each switch does:

  • An app stops answering sends one message when an incident opens, not one per check. It needs a paid plan.
  • Something new and serious turns up sends a message after the daily check, and only when something new qualifies. It never sends a daily message that all is well.
  • A finding is confirmed fixed sends a message when the check no longer finds a finding, or after a fix you asked for.

The severity decides what counts as serious. High, the default, means critical and high findings. Critical narrows it to critical findings. Medium adds medium findings and sends more messages. The same choice applies to the fixed message. A fix you asked for is told whatever its severity.

If you switch email alerts on before an address is saved, the switch waits for the address. The form reads Add the address and save to turn alerts on. and the next save puts it in force.

To stop alerts, turn Send alerts by email off. The message reads Saved, Alerts are off. The addresses stay saved, the three switches grey out, the card reads Paused while email alerts are off. Your choices below are kept., and the dot appears beside Alerts. On Home, the Company card shows Alerts as Off.

In the Inbox, Say where alerts go under Getting started leads to the same section until an address is in use.

What happens behind the scenes

  • The addresses belong to the company, not to a person. Vallit uses them for alerts and nothing else.
  • Home shows the main address to everyone in the company. In the company settings, only an admin sees the form and the switches; a member sees that only an admin can change where alerts go.
  • The main address is the one that counts. Its delivery is recorded, and a failed incident email is retried to it. The addresses under Also send to get the same message at the same moment, once, and a failure there changes nothing for the main address.
  • An address listed twice, in any capitalisation, gets one copy. With Send alerts by email off, or no main address saved, the extra addresses get nothing either.
  • Switches and the severity save the moment you change them, and go back if the save fails. Addresses wait for Save addresses.
  • There is no text message.
EmailSubjectWhen it is sentWhat it needs
An incident<app>: <what broke>When a check fails and an incident opens on the app's page.Paid plan, an alert address and An app stops answering on
New findings<app>: <n> new findings in today's checkWhen the daily full check finds something new, and at least one new finding is at or above the severity you chose. By default that is high.An alert address and Something new and serious turns up on
Fixed<app>: <n> fixed since yesterdayWhen a finding is gone since the last check and it was at or above your severity, or you asked us to fix it. Nothing at that level may be new.An alert address and A finding is confirmed fixed on
Fixed, after a recheck<app>: <title> fixedWhen a person at Vallit opens a finding, the same check runs again and no longer finds it.An alert address and A finding is confirmed fixed on
  • The incident email names what broke, the app and its address, and when it was first seen. It is sent once per incident, with no repeats while the incident lasts.
  • If an incident email cannot be sent, Vallit tries again with the next checks, up to three tries within a day.
  • A retry repeats the first email word for word, to the address it first went to. If the first try did arrive, the retry does not send it a second time. With alerts switched off, no further retries go out.
  • If the incident email bounces, cannot be delivered, or is marked as spam, Vallit does not send it to that address again. Vallit's team is told, so a person can reach you another way.
  • The new-findings email lists each new finding with its severity, anything fixed, the score and a link to the report. A finding from a targeted check on a domain you have not confirmed adds one line. It reads Confirm and the address, to see where it is and how to fix it. The email names that finding and its severity, and nothing more.
  • The fixed email lists what went away and says how many findings are still open, so it never reads as all clear.
  • After a recheck, the fixed email names the one finding. It starts We checked <app> (<host>) again, and it no longer finds this:. Nobody at Vallit has to confirm it first, and it is sent once per finding. We check again before we work on it explains the recheck.
  • With the switch off or no address saved, incidents still open and show on the app's page. Nobody gets an email.
  • A check you start yourself sends no email. Its report opens on the app's page.

How to tell an email is from Vallit

Every email from Vallit has the same shape, alerts and sign-in emails alike.

  • It comes from an address ending in @vallit.net.
  • It opens with a picture of the sky that fades into the page, with the Vallit icon below it. The sky tells you the kind of message before you read it.
  • It ends with The Vallit team.
  • A button always has its full address printed underneath, so you can see where it leads before you click. Vallit's links go to app.vallit.net or vallit.net.
  • Under the sign-off, the footer names Vallit, app.vallit.net and info@vallit.net, and links to the Impressum, the privacy policy and the Terms on vallit.net.
  • The last line of every email says that Vallit never asks for your password, a sign-in code or payment details by email, chat or phone. An email that asks for one of them is not from Vallit.
  • Many email apps hide pictures from a new sender until you allow them. The email then shows without the sky, and every word of it is still there.
The skyThe email
A calm dawnA report or a notice
A storm cloudAn incident
Light breaking through cloudsSomething is fixed or working again
A sun behind hazeNew findings, or a locked account
A deep blue sky before dawnA sign-in code or a change to your account
A sunrise over the cloudsAn invitation

What Vallit's team is told

Vallit's own team gets a short message in its Slack, so a person at Vallit sees what the checks find. These messages are for Vallit only: you do not receive them, and they change nothing in your company. A message goes out when:

  • a check of an app fails;
  • a check of an app on Watch or Care with a confirmed domain ends with checks that did not run. The message says how many, on which address, and why the first one did not run;
  • a check that a visitor started on vallit.net, or that you started, finds something rated Medium or higher;
  • the guardian's daily full check finds something new, or sees a finding fixed, since the check before;
  • an incident opens or closes on the app's page;
  • an incident email did not reach the alert address. The message says why, without the address;
  • someone in a company clicks Request fix;
  • the guardian's sample starts and finishes.

A message about a check carries the app's address, its score and the number of open findings at each severity. For a check you or a visitor started, it names the critical and high findings by title and severity. For a guardian check, it names the new findings with their severity and the fixed ones by title. A failed check adds the reason it stopped. An incident message names the check that failed and, once it closes, how long it lasted. A fix request adds the company's name and the finding's title and severity. The sample's messages count the apps it visits and name the address of any app where it reproduced a gap.

Each message opens with a colour the team reads at a glance. Red means a failure or a serious finding, yellow other findings, green fixes and quiet runs, and blue news. No message carries evidence, keys, report links or email addresses. Most link to Vallit's own console, which only Vallit's team can open. A message that fails to arrive never stops a check.

If something goes wrong

What you seeWhat it meansWhat to do
Only an admin of your company can change where alerts go.Your role in this company is not admin.Ask an admin to change it. Your company explains the roles.
Add the address and save to turn alerts on.The switch is on, but no address is saved yet.Enter an address and click Save addresses.
Add the address alerts should go to, or switch email alerts off.You saved with the switch on and the address field empty.Enter an address, or turn the switch off, then click Save addresses.
That does not look like an email address.The address is not complete, for example it has no ending such as .com.Correct the address and save again.
“…” does not look like an email address.One line under Also send to is not a complete address. The message names it.Correct that line and save again.
Add at most … more addresses.Also send to holds more than four addresses.Remove the extra lines and save again.
We could not save that. Try again in a moment.The change did not reach our side.Wait a minute, then click Save addresses again.
That did not go through. Check your connection and try again.A switch could not reach Vallit, so it went back to where it was.Check your connection, then flip the switch again.

If an email you expect does not arrive, look in the spam folder of the alert address.