SSL certificates
SSL certificate expiry monitoring, site by site
An expired certificate turns your client’s site into a browser warning page. It happens more often than you’d think, even with automatic renewal.
The problem
Automatic renewal breaks silently.
Let’s Encrypt and hosting companies renew certificates on their own, until something changes: DNS moved, a CDN added, an old certificate uploaded by hand. Renewal fails and nobody is told.
By the time you notice, visitors have seen “Your connection is not private” and your client has already emailed you.
How it works
We read the certificate the way a browser does.
- 1
TLS connection
Every day we connect to the site and read the certificate it presents, with its chain.
- 2
Checks
We check the expiry date, issuer, chain validity and that it matches the domain.
- 3
Early warning
You get a warning two weeks before expiry, a critical alert in the last week, and one straight away if the certificate is invalid.
In detail
Every certificate in one place.
- Expiry date and days left for every site
- Invalid, self-signed or wrong-domain certificates
- Warning and critical alerts that close on their own after renewal
- No plugin needed: checks start as soon as you add the URL
FAQ
Frequently asked questions
How early do SSL expiry alerts arrive?
Two weeks before, which leaves time to find out why automatic renewal didn’t run. In the last week the alert becomes critical, and it is critical at once if the certificate is invalid.
Does it work with Let’s Encrypt and Cloudflare?
Yes: we check the certificate the site actually presents to visitors, whoever issued it.
Related features
Goes well with
Try it on your clients’ sites.
During the beta we welcome agencies in small groups and set up the first sites together.