247Monitor

SSL certificate monitoring · expiry alerts

SSL monitoring that warns you in time.

A real TLS handshake on every check reads the certificate your visitors are actually served and counts down to its expiry. You hear about it weeks before it lapses, not from a customer screenshot of a browser warning.

Real handshakes · 30-day default warning · on the free plan

SSL monitor · shop.example.com

14days until expiry
warning · crossed 30-day threshold16d ago
Slack #ops + email sent16d ago
handshake OK · issuer R11 · checks continue2m ago

An expired certificate is a full outage, with a countdown written inside it.

Browsers turn an expired certificate into a full-screen warning almost nobody clicks through. Unlike most outages it is entirely predictable: the expiry date is in the certificate itself. SSL monitoring reads it on every check and makes sure the renewal that silently failed becomes an alert, not an incident.

What an SSL monitor watches.

Every check is a real handshake from outside your infrastructure, against the hostname you specify.

CheckWhat you seeAlert when
Expiry countdownDays remaining on the certificate each hostname actually servesThe countdown crosses your warning threshold (30 days by default)
Handshake healthA real TLS handshake on every check, from an external vantage pointThe handshake fails or the certificate is no longer valid
Certificate detailsIssuer, validity window and the certificate recorded at each checkReference data for investigations; no alerts
Origin hosts behind a proxyPoint a monitor at the origin directly, so a CDN's certificate can't mask yoursThe origin certificate, not the proxy's, crosses your threshold
Domain expiry (separate monitor)Registration expiry watched via registry data, alongside your SSL checksThe domain itself approaches expiry

Behind a CDN or proxy, the certificate a check sees is the proxy's, which its provider renews. Our origin-host guide shows how to point a second monitor at the certificate you renew yourself.

Warning thresholds

Weeks of notice, not a morning of panic.

The default warning fires 30 days out. Tune it per monitor: just below your automation's renewal point, with an urgent backstop at 7 days. Certificate lifetimes are shrinking toward 47 days, so the margin for a failed renewal keeps getting thinner.

ssl · www.example.com · 90-day certificate

updegraded · inside the warning windowdown · expired
Expiry isn't an event you discover; it's a runway you watch. The two alerts bracket the warning window: one you plan around, one you should never see.

Alerts

Alerts on the channels your team already watches.

SSL alerts route like every other check: email, SMS, Slack, Discord, Teams, Telegram and webhooks, with the same alert rules and maintenance windows.

  • A certificate crosses your warning threshold (30 days by default, configurable per monitor)
  • A certificate lapses, or the TLS handshake starts failing
  • Recovery, when a renewed certificate is being served again

Renewal that failed quietly

cert renewed automatically · 89 days leftMay
warning · 30 days left, renewal overdueJul
fixed the expired DNS credential · renewedJul

Certificates, uptime and servers on one dashboard.

SSL checks sit beside HTTP, keyword, DNS, domain-expiry, heartbeat and real-browser monitoring, sharing the same status pages and alert channels. New to the topic? Start with what SSL monitoring is or the expiry how-to.

See all monitor types →

FAQ

SSL monitoring questions.

How does 247Monitor check an SSL certificate?

Each SSL monitor performs a real TLS handshake against your hostname on every check, reads the certificate that is actually served and counts the days to expiry. You are warned when the countdown crosses your threshold and alerted immediately if the certificate lapses or the handshake fails.

What warning threshold should I set?

The default is 30 days, a sensible choice for annually renewed certificates. If automation such as Let's Encrypt renews around 30 days out, set the warning just below it (about 21 days) so an alert means renewal has already failed, and add an urgent rule at 7 days as the backstop.

I use auto-renewal. Do I still need SSL monitoring?

Yes. Auto-renewal fails quietly: an expired credential, a changed DNS record or a rate limit stops the renewal without stopping your site, until the certificate runs out. Monitoring the served certificate is how you find out while there is still time to fix it calmly.

Is SSL monitoring included on the free plan?

Yes. The free plan includes 25 monitors and SSL certificate checks are one of the included types, with the 30-day warning threshold and six non-SMS alert integrations. No card required.

No credit card · 25 monitors free

Start monitoring in minutes.

The free plan includes 25 monitors, one server and a public status page. Add your first check and choose where alerts should be sent.