Skip to content
Certificates and domains

The outages that have a dateand can be prevented in advance.

An expired certificate or a forgotten domain renewal is a completely predictable outage. A TLS monitor measures validity, issuer and days remaining, and warns before the deadline.

Free plan: 3 monitors and one vantage point · 14-day Pro trial

What gets measured

Certificate validity

Is the certificate valid, issued for this name, and part of a trusted chain?

Days remaining

The time to expiry is computed and shown, not just a yes/no.

Issuer

You can see who issued it; a sudden change is itself a signal.

Domain expiry

For domains, the expiry date comes from the registry's RDAP service.

Expiry warnings are not outages

An approaching deadline is a warning, not downtime.

A separate incident type

When the days remaining fall below the threshold, an expiry incident opens on its own.

Configurable threshold

Thirty days by default, set separately for certificates and domains.

Availability untouched

An approaching expiry never marks the monitor down, so your uptime figure stays honest.

A limit worth knowing

This one is not ours to fix.

.ir domains do not publish expiry

The Iranian registry, and most Middle Eastern country domains, do not make that date publicly available.

Reported as unknown, not failed

In that case the expiry state is recorded as undetermined instead of raising a false alarm.

No service can work around it

The limit is the registry's; any tool showing a number there has guessed it from somewhere else.

Where this stops

Internal certificates

If an internal CA issued your certificate you can turn verification off, but then this condition no longer means anything.

That host only

The certificate checked is the one on the address the monitor connects to, not every subdomain.

Related features

Take one expiry date off your mind

Add a monitor for your main domain and certificate and let the reminder be ours.

Create a free account