If the SSL certificates you are monitoring are protected by a web application firewall or other service that could block our monitoring agent, you will need to whitelist the IP address we use to monitor. Here is a list of IPs we could use to connect:
138.68.190.144
209.71.64.209
2a09:8280:e601:1:0:da:b99a:0
Or check it here at https://trackssl.com/ips.txt
This list is updated whenever new monitoring hosts are deployed. Ideally, your solution should pull that list programmatically once per day but we will update that list and this page at least one month before changing IPs.