SSL certificate monitoring that catches expiry before your users do
One expired certificate puts a browser warning in front of every visitor and fails every API client at once. Get warned a configurable number of days ahead, with time to renew calmly.
A warning window you control
Set how many days before expiry each certificate should start warning you. Renew on your schedule instead of scrambling on expiry day.
Any host, any port
The port defaults to 443 but is fully configurable, so you can watch certificates on anything that serves TLS, with a timeout you set per monitor.
Alerts where you'll see them
Route SMS, email, or Discord alerts per monitor. Choose down alerts, recovery notices, or both, with message templates you can customize.
Checks every minute
Certificates are checked every minute by default, with the interval configurable per monitor. Outages are tracked as incidents from first failed check to recovery.
How it works
- 1
Add an SSL monitor
Enter the host you want to watch. The port defaults to 443, and you can set a custom port and timeout.
- 2
Set your warning window
Choose how many days before expiry you want to be warned, with enough time to renew without a fire drill.
- 3
Route your alerts
Pick SMS, email, or Discord per monitor and you're covered. Checks run every minute from then on.
Frequently asked questions
How far in advance am I warned before a certificate expires?
That's up to you. Every SSL monitor has a configurable warn-days setting: tell it how many days of notice you need, and you're warned as soon as the certificate's remaining lifetime drops inside that window.
Which alert channels fire when a certificate is about to expire?
SMS, email, and Discord. Alerts are routed per monitor, so a production certificate can text you while less critical hosts post to a Discord channel. You choose down alerts, recovery notices, or both, and message templates are customizable per channel.
Can I check certificates on non-standard ports?
Yes. The port defaults to 443 but is fully configurable, so you can watch certificates on any host and port that serves TLS, not just public websites. Each monitor also has its own timeout.
Why is an expired certificate so damaging?
Browsers block the page with a full-screen security warning most visitors won't click through, and API clients, mobile apps, and integrations fail the TLS handshake outright. Everything breaks at once, which is why you want a warning well before expiry, not after.