SSL monitoring
SSL certificate monitoring that warns before the padlock breaks
SSL certificate monitoring checks the TLS certificate a hostname presents, records when it expires and warns you before it does. MoniterMySite reads the certificate on every check, counts down the days remaining, sends reminders at 30, 14, 7, 3 and 1 day plus your own threshold, and treats an expired certificate as an outage.
- Expiry reminders at 30, 14, 7, 3 and 1 day before the certificate runs out, plus a threshold you choose
- Chain and hostname validation on HTTP monitors, so an invalid certificate fails the check
- Works on any hostname and port, with the issuer, subject and expiry date recorded on every check

How it works
Add the hostname
Create an SSL certificate monitor and enter the hostname. Port 443 is assumed; append a port such as mail.example.com:993 to check a different service. Set how many days before expiry you want your own warning.
We read the certificate
On every check a probe opens a TLS connection, reads the certificate the server presents and records its issuer, subject and expiry date. The days remaining are shown on the monitor page.
Reminders count down
As expiry approaches, each attached contact receives a reminder when 30, 14, 7, 3 and 1 day remain, and at the threshold you set. Each milestone is sent once, so a renewal silences the countdown.
An expired certificate is an outage
If the certificate passes its expiry date the check fails, an incident opens and your contacts receive a down alert, exactly as for a website that stopped responding.
What you get
Reminder schedule
Fixed milestones at 30, 14, 7, 3 and 1 day, plus the monitor's own threshold (14 days by default, settable from 1 to 90). Reminders go to the same contacts as down alerts.
Chain and hostname validation
HTTP(S) monitors validate the certificate by default. A chain that does not lead to a trusted root, or a certificate issued for a different hostname, fails the check and opens an incident.
Expiry tracking on HTTP monitors too
You do not need a separate SSL monitor for a site you already check over HTTPS: HTTP and Keyword monitors record the certificate expiry and receive the same reminders.
Any port
Check SMTP, IMAP, database or custom TLS services by adding the port to the hostname. The default is 443.
Every channel
Certificate reminders are delivered to email and webhooks on every plan, to Slack, Discord, Teams, Google Chat and Telegram from Launch, and to PagerDuty from Growth. Webhook payloads carry the event ssl_expiry.
Why certificate expiry still takes sites down
Certificates expire on a known date, which is exactly why they get forgotten. The engineer who set up renewal leaves, an automated renewer loses access to the DNS API, a wildcard certificate is replaced everywhere except one load balancer, or an internal service nobody looks at quietly stops accepting connections. When the date arrives every browser shows a full-page warning, every API client refuses to connect, and nothing in your logs explains why traffic fell to zero.
Monitoring the certificate itself, rather than hoping renewal worked, turns that cliff edge into a series of reminders. Thirty days out is early enough to fix a broken renewer; one day out is a final chance before customers notice. Because the monitor reads what the server actually presents, it also catches the case where a new certificate was issued but never deployed.
What the SSL monitor checks
A dedicated SSL certificate monitor is one TLS handshake per interval, with no page load. It records and alerts on the following:
- The expiry date and the number of days remaining, recorded on every check
- The issuer and subject of the presented certificate
- Expired: the check fails and an incident opens
- Unreachable: if no certificate can be retrieved within the timeout, the check fails
- Your own warning threshold in days, on top of the fixed 30, 14, 7, 3 and 1 day reminders
Reminder schedule
Reminders are sent to every contact attached to the monitor. Each milestone fires once; renewing the certificate resets the countdown.
| Days before expiry | What is sent |
|---|---|
| Your threshold (1 to 90 days, default 14) | SSL expiring reminder |
| 30 days | SSL expiring reminder |
| 14 days | SSL expiring reminder |
| 7 days | SSL expiring reminder |
| 3 days | SSL expiring reminder |
| 1 day | SSL expiring reminder |
| Expired | Down alert and an incident |
Plans and limits
An SSL monitor counts as one monitor on any plan. Because a certificate changes rarely, the Starter interval of 5 minutes is enough for most teams; faster intervals matter more for HTTP monitors.
| Plan | Price per month | Monitors | Fastest check | Alert channels |
|---|---|---|---|---|
| Starter | Free | 10 | 5 minutes | Email, webhook |
| Launch | $9 ($7.50 yearly) | 100 | 60 seconds | Adds Slack, Discord, Teams, Google Chat, Telegram |
| Growth | $29 ($24 yearly) | 200 | 30 seconds | Adds PagerDuty |
| Summit | $79 ($65 yearly) | 1,000 | 10 seconds | All eight |
Frequently asked questions
How far in advance will I be warned that a certificate is expiring?
At 30, 14, 7, 3 and 1 day before expiry, and at your own threshold, which defaults to 14 days and can be set anywhere from 1 to 90. Each reminder is sent once to every contact attached to the monitor.
Does an HTTP monitor already track the certificate?
Yes. HTTP and Keyword monitors validate the certificate on every request when SSL validation is on, record its expiry date, and receive the same 30, 14, 7, 3 and 1 day reminders. A separate SSL monitor is useful for hosts you do not otherwise check, or for non-HTTP ports.
Can I monitor a certificate on a port other than 443?
Yes. Enter the hostname followed by the port, for example imap.example.com:993 or db.example.com:5432, and the monitor performs the TLS handshake on that port.
What happens when the certificate actually expires?
The check fails, the monitor goes down, an incident is opened and your contacts receive a down alert. When a valid certificate is deployed the next check succeeds, the incident is resolved and a recovery message is sent.
Will short-lived certificates from automated issuers generate constant reminders?
Reminders only fire when the presented certificate is within a milestone and that milestone has not already been sent for it. If your renewer replaces the certificate before the 30-day mark you will not hear from us at all; if it fails, you will.
Keep reading
Start monitoring in 30 seconds.
Nothing to install. No credit card. 10 monitors free, forever.