SSL monitoring

SSL certificate monitoring that warns before the padlock breaks

SSL certificate monitoring checks the TLS certificate a hostname presents, records when it expires and warns you before it does. MoniterMySite reads the certificate on every check, counts down the days remaining, sends reminders at 30, 14, 7, 3 and 1 day plus your own threshold, and treats an expired certificate as an outage.

  • Expiry reminders at 30, 14, 7, 3 and 1 day before the certificate runs out, plus a threshold you choose
  • Chain and hostname validation on HTTP monitors, so an invalid certificate fails the check
  • Works on any hostname and port, with the issuer, subject and expiry date recorded on every check
SSL certificate monitor detail page for monitermysite.com showing the certificate expiry date, days remaining and check history
One of our own monitors for monitermysite.com, as shown in the dashboard.

How it works

  1. Add the hostname

    Create an SSL certificate monitor and enter the hostname. Port 443 is assumed; append a port such as mail.example.com:993 to check a different service. Set how many days before expiry you want your own warning.

  2. We read the certificate

    On every check a probe opens a TLS connection, reads the certificate the server presents and records its issuer, subject and expiry date. The days remaining are shown on the monitor page.

  3. Reminders count down

    As expiry approaches, each attached contact receives a reminder when 30, 14, 7, 3 and 1 day remain, and at the threshold you set. Each milestone is sent once, so a renewal silences the countdown.

  4. An expired certificate is an outage

    If the certificate passes its expiry date the check fails, an incident opens and your contacts receive a down alert, exactly as for a website that stopped responding.

What you get

Reminder schedule

Fixed milestones at 30, 14, 7, 3 and 1 day, plus the monitor's own threshold (14 days by default, settable from 1 to 90). Reminders go to the same contacts as down alerts.

Chain and hostname validation

HTTP(S) monitors validate the certificate by default. A chain that does not lead to a trusted root, or a certificate issued for a different hostname, fails the check and opens an incident.

Expiry tracking on HTTP monitors too

You do not need a separate SSL monitor for a site you already check over HTTPS: HTTP and Keyword monitors record the certificate expiry and receive the same reminders.

Any port

Check SMTP, IMAP, database or custom TLS services by adding the port to the hostname. The default is 443.

Every channel

Certificate reminders are delivered to email and webhooks on every plan, to Slack, Discord, Teams, Google Chat and Telegram from Launch, and to PagerDuty from Growth. Webhook payloads carry the event ssl_expiry.

Why certificate expiry still takes sites down

Certificates expire on a known date, which is exactly why they get forgotten. The engineer who set up renewal leaves, an automated renewer loses access to the DNS API, a wildcard certificate is replaced everywhere except one load balancer, or an internal service nobody looks at quietly stops accepting connections. When the date arrives every browser shows a full-page warning, every API client refuses to connect, and nothing in your logs explains why traffic fell to zero.

Monitoring the certificate itself, rather than hoping renewal worked, turns that cliff edge into a series of reminders. Thirty days out is early enough to fix a broken renewer; one day out is a final chance before customers notice. Because the monitor reads what the server actually presents, it also catches the case where a new certificate was issued but never deployed.

What the SSL monitor checks

A dedicated SSL certificate monitor is one TLS handshake per interval, with no page load. It records and alerts on the following:

  • The expiry date and the number of days remaining, recorded on every check
  • The issuer and subject of the presented certificate
  • Expired: the check fails and an incident opens
  • Unreachable: if no certificate can be retrieved within the timeout, the check fails
  • Your own warning threshold in days, on top of the fixed 30, 14, 7, 3 and 1 day reminders

Reminder schedule

Reminders are sent to every contact attached to the monitor. Each milestone fires once; renewing the certificate resets the countdown.

Days before expiryWhat is sent
Your threshold (1 to 90 days, default 14)SSL expiring reminder
30 daysSSL expiring reminder
14 daysSSL expiring reminder
7 daysSSL expiring reminder
3 daysSSL expiring reminder
1 daySSL expiring reminder
ExpiredDown alert and an incident

Plans and limits

An SSL monitor counts as one monitor on any plan. Because a certificate changes rarely, the Starter interval of 5 minutes is enough for most teams; faster intervals matter more for HTTP monitors.

PlanPrice per monthMonitorsFastest checkAlert channels
StarterFree105 minutesEmail, webhook
Launch$9 ($7.50 yearly)10060 secondsAdds Slack, Discord, Teams, Google Chat, Telegram
Growth$29 ($24 yearly)20030 secondsAdds PagerDuty
Summit$79 ($65 yearly)1,00010 secondsAll eight

Frequently asked questions

How far in advance will I be warned that a certificate is expiring?

At 30, 14, 7, 3 and 1 day before expiry, and at your own threshold, which defaults to 14 days and can be set anywhere from 1 to 90. Each reminder is sent once to every contact attached to the monitor.

Does an HTTP monitor already track the certificate?

Yes. HTTP and Keyword monitors validate the certificate on every request when SSL validation is on, record its expiry date, and receive the same 30, 14, 7, 3 and 1 day reminders. A separate SSL monitor is useful for hosts you do not otherwise check, or for non-HTTP ports.

Can I monitor a certificate on a port other than 443?

Yes. Enter the hostname followed by the port, for example imap.example.com:993 or db.example.com:5432, and the monitor performs the TLS handshake on that port.

What happens when the certificate actually expires?

The check fails, the monitor goes down, an incident is opened and your contacts receive a down alert. When a valid certificate is deployed the next check succeeds, the incident is resolved and a recovery message is sent.

Will short-lived certificates from automated issuers generate constant reminders?

Reminders only fire when the presented certificate is within a milestone and that milestone has not already been sent for it. If your renewer replaces the certificate before the 30-day mark you will not hear from us at all; if it fails, you will.

Start monitoring in 30 seconds.

Nothing to install. No credit card. 10 monitors free, forever.