SSL Certificate Monitoring

Never get caught out by an expired certificate.

An expired SSL/TLS certificate takes your website offline and shows every visitor a security warning — usually on a weekend, usually because a renewal that had worked for years quietly stopped. I check every certificate you rely on daily and warn you at 30, 14 and 7 days, or renew it for you entirely.

Why it happens

Nobody lets a certificate expire on purpose.

It is almost always one of three things, and none of them announce themselves.

Auto-renewal quietly stops working

A DNS change, a moved website, an expired API key at the host, a firewall rule — any of them can break the renewal job, and nothing tells you until the certificate runs out.

The reminder goes to the wrong person

Renewal emails land with whoever set the site up: a former employee, an old web agency, a mailbox nobody opens. Let’s Encrypt stopped sending expiry emails altogether in 2025.

Certificates are getting shorter

The maximum lifetime of a public certificate is being cut from 398 days to 200 in 2026, 100 in 2027 and 47 in 2029. A yearly diary reminder stops being enough.

What's checked

The certificate the world actually sees.

Not what the renewal job reports — what a browser connecting from outside gets served, every day.

  • Days until expiry on every certificate you rely on — the website, the client portal, any mail or remote-access hostnames
  • That the certificate presented actually matches the hostname (a common failure after a migration)
  • That the full chain is served, so it works in every browser and on every phone, not just the one you tested on
  • Weak protocols and ciphers still enabled, which some cyber insurance questionnaires and Cyber Essentials Plus scans will pick up
  • A daily check, not a one-off scan — because the certificate that was fine last month is the one that expires on a Saturday
How the alerts work

Three warnings, to the right people.

Each alert goes to you and to me, so a reminder never depends on one inbox.

30 days out

A heads-up. Plenty of time to renew normally or ask me to.

14 days out

A second reminder if nothing has changed.

7 days out

A final warning, to both you and me, so it cannot slip through.

Expired

Immediate alert if a certificate has lapsed, with what visitors are now seeing.

What's changing

A yearly reminder is about to stop being enough.

The CA/Browser Forum — the certificate authorities and browser makers who set the rules — voted in 2025 to cut the maximum lifetime of a public certificate in stages. Renewal goes from once a year to several times a year, and eventually to roughly every six weeks.

Today
398 days
maximum validity
From March 2026
200 days
maximum validity
From March 2027
100 days
maximum validity
From March 2029
47 days
maximum validity

Shorter certificates limit the damage if one is stolen, which is good. They also mean the renewal has to be automated and the automation has to be watched — which is the point of this page.

Part of External Security Monitoring

Certificate monitoring is one strand of a wider service that watches everything about your business that faces the internet: DNS, domain registration and expiry, email security (SPF, DKIM and DMARC) and whether your website and portal are actually up. It is priced per domain, and the certificate checks come with it.

See External Security Monitoring
FAQ

Common questions

What happens when an SSL certificate expires?+

Every visitor sees a full-page browser warning saying the site is not secure, and most will leave. Search engines note it. Anything else using that certificate — a customer portal, a mail server, a remote-access gateway — fails at the same time, often with a much less obvious error. It is one of the few outages that is entirely preventable and entirely avoidable with a reminder that reaches the right person.

My hosting renews the certificate automatically. Do I still need monitoring?+

Automatic renewal is the right setup and most of the time it works. Monitoring is for the times it does not: the renewal job breaks after a DNS change, a plugin update, a move to a new host or an expired token, and nothing tells you. Monitoring checks the certificate the world actually sees, every day, regardless of what the renewal job thinks it did.

Which certificates should be monitored?+

Anything with a public hostname your business or your customers connect to: the website, any client or booking portal, the mail server hostname your phones connect to, a VPN or remote desktop gateway, and any subdomains in use. Most small businesses have between two and five. I will find them as part of the first check.

Can you renew certificates for me as well?+

Yes. Monitoring on its own just tells you in time. On the managed option I renew and install the certificate for you when it comes up, and fix whatever broke the automatic renewal so it does not happen again.

Why are certificate lifetimes getting shorter?+

The CA/Browser Forum, the group of certificate authorities and browser makers that sets the rules, voted in 2025 to reduce the maximum validity of public certificates in stages: 200 days from March 2026, 100 days from March 2027 and 47 days from March 2029. Shorter lifetimes limit the damage if a certificate is stolen, but they mean renewal happens several times a year and has to be automated — and watched.

Want your certificates watched?

Start with a free check: I will list every certificate your business relies on, when each one expires, and anything already wrong with them.

Book a free perimeter check