Why expired certs still happen
- DNS validation breaks after a registrar change.
- Renewal cron jobs silently fail on a migrated host.
- Acme rate limits suspend renewal for 7 days.
- An admin removes the renewal workflow during a cleanup.
Expired SSL certificates are one of the most preventable outages on the web. A quiet monitor that warns you 14 days ahead turns a Sunday-morning incident into a Tuesday-afternoon ticket. Here's how to set it up.
"SSL certificate for example.com expires in 10 days." That's enough detail to act on — no panic copy, no red banners. Once you renew, the next monitor run clears the alert automatically.
Run through these steps in order. Each step links to the right diagnostic tool.
14 days is comfortable for most teams. 30 days for slow change-control environments. 3 days should be a critical alert.
Still monitor it. Auto-renewal silently fails when DNS validation breaks or rate limits kick in — the monitor is your last line of defense.
No. Monitor the public hostname that customers actually see. The cert's other SANs renew on the same schedule.
Only public, internet-reachable hosts. Internal CAs need an internal monitoring tool.
Monitor it continuously
Save this check, get alerts on changes, and track multiple domains in one dashboard.