Your site is down. Here's what to do in the next 30 minutes.
Work the triage checklist below before you pay anyone. It is the same sequence IG Digital Lab runs on every emergency call, and it separates the three things this almost always turns out to be: something expired, something broke, or somebody got in. If you would rather we ran it, the phone is answered now.
Answered 24 hours a day by our AI receptionist, which takes the details and escalates a live outage to a person.
What should I check first when my website is down?
Start by confirming the site is down for everyone and not just you. Then check the four causes behind most outages: an expired domain, an unpaid hosting invoice, an expired certificate, and a change somebody made in the last two days. IG Digital Lab runs this same triage on every emergency call we take in Sacramento.
-
Confirm it is down for everyone
Open the site on your phone with Wi-Fi turned off, and ask someone across town to try it. A checker such as downforeveryoneorjustme.com gives a second opinion. If it loads for everyone but you, the problem is your network, your browser cache or your local DNS, and the site itself is fine.
-
Check that the domain has not expired
Run a WHOIS lookup on your domain and read the expiration date. An expired domain takes a working site offline within hours and often leaves an advertising parking page in its place. Renewing fixes it, although DNS can take a few hours to settle afterward.
-
Check that DNS still resolves
A domain that is paid up can still point nowhere. If the browser says the address could not be found, the DNS records were changed, deleted or moved to another provider. Find out who edited DNS recently and where the nameservers point now.
-
Check the hosting invoice
Suspended hosting is one of the most common causes we see, and it is usually an expired card on file rather than a decision. Log into the hosting account, look for unpaid invoices or a suspension notice, and check the billing mailbox including the spam folder.
-
Check the SSL certificate
If visitors get a full page warning that the connection is not private, the certificate expired or stopped renewing. The site behind it is usually intact. Note the exact wording of the warning, because it tells us which piece failed.
-
Read the actual error
A 500 means the application crashed. A 502 or 504 means the server is up but the application behind it is not answering. A connection timeout points at the server or its firewall. Server not found points at DNS. Screenshot whichever one you get.
-
Ask what changed in the last 48 hours
Plugin and theme updates, a deployment, a DNS edit, a migration, a canceled subscription, a staff departure. Most outages start with a change, and knowing the change usually shortens the fix from hours to minutes.
-
Look for signs of a break-in
Redirects to a site you do not recognize, admin users nobody created, pages you never wrote, a warning next to your listing in Google, or an abuse email from your host. If you see any of these, treat it as a hack and stop changing things.
-
Write down who has access, screenshot everything, delete nothing
List who holds the registrar login, the hosting login, DNS and the site admin. Screenshot every error and save every email. Deleting files, reinstalling the platform or restoring a random backup over a hacked site destroys the evidence needed to find the cause.
Is it hacked, expired, or broken? How to tell
Expired things fail at a specific moment and there is a billing email to match. Hacks change what visitors see rather than whether the site loads. Broken code fails right after somebody changed something. IG Digital Lab treats the three differently, because restoring a hacked site from backup without finding the way in only rebuilds the same door.
It expired
The domain, the hosting plan or the certificate ran out. The site went from fine to gone at a precise moment, nothing in the code changed, and a failed payment notice is sitting in somebody's inbox. Cheapest kind of outage to fix and the easiest to prevent for good.
It was hacked
Visitors get bounced to a site you have never heard of, search results show pages in a language you do not sell in, there are admin accounts nobody created, or the host suspended you for sending spam. It often still looks normal when you are logged in.
It broke
A plugin or theme update, a deployment, a database or language version bump. The symptom is usually a 500 error or a blank white page, and the timing lines up with something a human did. Rolling that change back is frequently the entire fix.
What do you do when we call, and in what order?
We stabilize first, restore second, and explain last. That order is deliberate: the fastest way to lose a day is to start hunting root cause while your customers are still staring at an error page. IG Digital Lab gets you visible again, then works out what happened, then closes the hole.
Stabilize
Get something in front of visitors, even if the first version is a holding page with your phone number and hours. If a renewal, a restart or a rollback brings the site straight back, we do that immediately and tell you exactly what we changed.
Restore
Bring the site back from the most recent clean backup, then verify that recent content, orders and form submissions actually survived. If the backups are missing, stale or already infected, we say so plainly instead of quietly restoring a compromised copy.
Find the root cause
Server, application and access logs say what really happened and when. Skipping this step is how a site goes down three times in a month and looks like three unrelated problems, and how the same bill arrives three times.
Secure
Rotate every password and key, remove unknown admin users and backdoors, patch what was out of date, and close the path that was used. If customer data may have been exposed, we document what we found so you and your attorney can decide what has to be disclosed.
Monitor
Uptime, certificate expiry, domain renewal dates and backup success go on a monitor, so the next problem is something we call you about rather than something a customer reports on a Saturday.
Hand back
A short written summary: what happened, what we changed, where the backups live now, and which logins you own. Everything stays in your accounts, so you are never stuck waiting on us the next time.
What does emergency website help cost?
Emergency work is billed at our hourly rate, $150 to $200 per hour, and most outages are resolved in a few hours rather than days. You get the number before we start, not on an invoice afterward. If the fix turns out to be a five minute renewal you can do yourself, we will tell you that and charge you nothing.
Keeping the site up after that is a Care plan at $300 to $500 per month, covering monitoring, updates, backups and the small fixes that otherwise pile up until they become the next outage. It is optional, and larger builds have their own pricing.
How do you keep this from happening again?
Nearly every outage we are called about was preventable and cheap to prevent: monitoring that warns you before customers do, backups that get tested rather than assumed, updates on a schedule, and renewals on somebody's calendar. That is what our servers and support service does, month to month.
Monitoring and tested backups
Uptime checks from outside your network, alerts that reach a human, and backups that are restored on a test schedule so you learn they work before you need them.
Renewals nobody forgets
Domain, certificate and hosting renewals tracked with the billing card kept current, and the registrar account in your name rather than a former contractor's.
Documented access and patching
One written record of every account, who holds it and what it controls, plus updates applied on a schedule instead of whenever something already broke.
Emergency questions we get asked
What people ask in the first five minutes of a call about a site that is offline.
My site is down right now. How quickly can you look at it?
Call (916) 618-0502. The line is answered 24 hours a day by our AI receptionist, which takes the details and escalates a live outage to a person. You get a straight answer about when we can start, and if we cannot get to it soon enough to be useful, we tell you that instead of holding the ticket.
I do not have the hosting or domain logins. Can you still help?
Usually yes. Public records show which registrar and host your domain uses, and account recovery runs through the owner, so we help you take control back rather than work around it. Old invoices and emails from the previous developer are worth digging up, because they often name the accounts we need.
The site was hacked. Do I have to tell my customers?
That depends on whether personal information was exposed, and it is a legal question rather than a technical one. We document what we find, including which files and accounts were touched and when, so you and your attorney can decide. We do not make that call for you.
Do I have to sign a monthly contract to get emergency help?
No. Emergency work is hourly and stands on its own, at $150 to $200 per hour with the estimate given before we start. A Care plan afterward is optional. It exists because the second outage is usually a repeat of the first one.
Can you take over from a host or developer who stopped answering?
Yes, and it is a different job from an outage. Taking over means getting your domain, code, hosting and analytics back into accounts you own, then making the site maintainable again. Our website takeover page walks through how that transfer works.
Down right now? Call, and we will start with the checklist.
(916) 618-0502, answered day and night, escalated to a person for a live outage. If it is not urgent, book the free audit and we will find what is fragile before it takes the site down.
Call (916) 618-05023550 Watt Ave, Suite 408, Sacramento, CA 95821. Remote work nationwide.