The outages that have a dateand can be prevented in advance.
An expired certificate or a forgotten domain renewal is a completely predictable outage. A TLS monitor measures validity, issuer and days remaining, and warns before the deadline.
Free plan: 3 monitors and one vantage point · 14-day Pro trial
What gets measured
Certificate validity
Is the certificate valid, issued for this name, and part of a trusted chain?
Days remaining
The time to expiry is computed and shown, not just a yes/no.
Issuer
You can see who issued it; a sudden change is itself a signal.
Domain expiry
For domains, the expiry date comes from the registry's RDAP service.
Expiry warnings are not outages
An approaching deadline is a warning, not downtime.
A separate incident type
When the days remaining fall below the threshold, an expiry incident opens on its own.
Configurable threshold
Thirty days by default, set separately for certificates and domains.
Availability untouched
An approaching expiry never marks the monitor down, so your uptime figure stays honest.
A limit worth knowing
This one is not ours to fix.
.ir domains do not publish expiry
The Iranian registry, and most Middle Eastern country domains, do not make that date publicly available.
Reported as unknown, not failed
In that case the expiry state is recorded as undetermined instead of raising a false alarm.
No service can work around it
The limit is the registry's; any tool showing a number there has guessed it from somewhere else.
Where this stops
Internal certificates
If an internal CA issued your certificate you can turn verification off, but then this condition no longer means anything.
That host only
The certificate checked is the one on the address the monitor connects to, not every subdomain.
Related features
Take one expiry date off your mind
Add a monitor for your main domain and certificate and let the reminder be ours.
Create a free account