SSL certificate monitoring: a warning before the browser shows one
An expired certificate is the only outage whose exact minute you know in advance, and it still lands on a Saturday morning. Uptimo reads the expiry date and the issuer from every monitored https address and warns you as many days ahead as you choose. No separate service to set up, and it is in every plan, including the free one.
What happens in the minute a certificate expires
This is not a service slowly getting worse. Everything works until the last second, and then the browser stops letting anyone through.
A full screen warning instead of your site
The visitor sees a message about an unsafe connection and a button to go back. Getting through means deliberately ignoring a security warning, which almost nobody does.
Integrations stop talking to you
The payment gateway, the courier and the warehouse system refuse the connection, because they verify certificates more strictly than a browser. Orders stop arriving while the server is up and answering.
Transactional messages bounce
Notifications sent through a service that uses the same certificate stop being delivered, usually without a readable reason.
Trust returns slower than the certificate
Renewing takes fifteen minutes. A customer who saw a warning about an unsafe site comes back much later, or never.
What the check looks like in Uptimo
There is no separate certificate service to create. Every monitored https address is checked for this as well, so you cannot add a site and forget about its certificate.
The alert channels are the same as for an outage: e-mail, Slack, Microsoft Teams, SMS and webhook, with escalation and an acknowledgement. A certificate is the one case where the alert arrives ahead of the problem instead of after it.
Why a calendar reminder is not enough
A calendar entry is created once, at launch, and knows only that one date. A certificate replaced in a hurry mid year moves the deadline while the entry stays as it was. A calendar also belongs to a person rather than to a service, so when someone changes jobs the reminder leaves with them. The check reads the real state from the server on every run, so there is nothing to keep up to date by hand.
Automatic renewal can fail quietly too
Free certificates renew themselves as long as everything lines up. Change an IP address, add a redirect that blocks the verification, leave the renewal service off after a restart or hit a limit at the issuer, and the process stops working without telling anyone. Automation is convenient, but it is not monitoring: it reports that it tried, not that a valid certificate is on the server.
What certificate monitoring costs
Close to nothing, because this check takes us milliseconds. You pay for browser scenarios, which run a real browser.
If certificates are all you need, the free plan covers it and asks for no card. A paid plan makes sense once you also want to know whether the customer can actually buy.
What this check does not do
- It does not watch domain expiry. That is a separate date at a separate provider; set a reminder with your registrar if you need it.
- We do not renew the certificate for you. We have no access to your server and do not want any; we only say when it is time to act.
- We read the expiry date and the issuer. We do not grade the encryption and we do not check revocation.
- We check from one location in the European Union. A certificate served incorrectly to only some visitors can look fine from here.
What people ask before turning it on
It depends on how long a replacement takes you. With automatic renewal, seven days is enough, because the warning means the automation stopped working. With a certificate bought from a provider, thirty is safer, because validation and an invoice are involved. The threshold is set per service.
As many as the addresses you really want watched. A shared certificate expires for all of them at once, but each address can stop serving it correctly on its own, for example after one server is reconfigured.
The issuer and the expiry date come from the current connection, so after a renewal the date on the dashboard jumps to the new one. That is usually the first proof that automatic renewal did its job.
Reading the certificate is part of monitoring an https address. For other services you use a TCP port check, which tells you the service is listening but does not read a certificate from it.
A certificate warning arrives days ahead, so it lands in a normal working day rather than in a night shift. Escalation and maintenance windows work exactly as they do for the other checks, if you want to tune it further.
Find out when your certificates really expire
Create a free account, paste three https addresses and look at the expiry dates and issuers. It takes fifteen minutes and needs no card.