Read more articles
SSLPublished January 10, 2025 · Updated September 28, 2026

SSL certificate monitoring: prevent expiry outages

SSL certificate monitoring explained: why certificates expire faster, what to check beyond the expiry date and how to get alerts before users see errors.

SSL certificate monitoring checks your website's certificates automatically and warns you before an expired or misconfigured certificate triggers browser warnings and turns visitors away. Strictly speaking, today's certificates are TLS certificates, but "SSL" is still the common name. This guide covers why certificate monitoring matters more as lifetimes shrink, what to check and how to set it up. It is one part of a complete website monitoring setup.

Why SSL certificates matter

A certificate proves that visitors are talking to your real server and encrypts everything they send. When it expires or fails validation, browsers show a full-page security warning, and APIs and mobile apps usually refuse to connect at all.

Security

  • Encrypts data in transit between visitors and your server
  • Protects logins, form submissions and payment details
  • Proves the server's identity, which prevents man-in-the-middle attacks
  • Ensures data is not altered on the way

Search and user trust

  • Google has used HTTPS as a ranking signal since 2014 (Google Search Central, 2014)
  • Major browsers label plain HTTP pages as "Not secure"
  • Certificate errors stop visitors on a warning page before your site loads
  • Browser features such as service workers and HTTP/2 require HTTPS

Why certificate lifetimes are getting shorter

Certificate lifetimes are being cut in stages. In April 2025 the CA/Browser Forum approved ballot SC-081v3, which lowers the maximum validity of publicly trusted TLS certificates (CA/Browser Forum, 2025):

  • 200 days for certificates issued from 15 March 2026
  • 100 days for certificates issued from 15 March 2027
  • 47 days for certificates issued from 15 March 2029

Let's Encrypt, whose default certificates are valid for 90 days, plans to move to 45 days by February 2028 (Let's Encrypt, 2025). Shorter lifetimes mean more renewals per year, and every renewal is a chance for automation to fail quietly. That makes monitoring more important, not less.

Certificate lifecycle

Issued→Valid→Renewal due→Expired

What to check beyond the expiry date

Expiry is the most common failure, but not the only one. A useful SSL certificate monitoring setup watches for these problems:

Common SSL certificate problems

  • Expiry: the certificate's end date, compared with your renewal schedule
  • Hostname mismatch: the certificate does not cover the name being visited, for example www versus the bare domain
  • Incomplete chain: a missing intermediate certificate, which some browsers and most API clients reject
  • Untrusted or revoked certificates: self-signed certificates in production, or certificates revoked by the issuing CA
  • Weak configuration: deprecated protocol versions such as TLS 1.0 and 1.1, or weak keys and cipher suites
  • Renewal that never deployed: a new certificate was issued, but the server, load balancer or CDN still serves the old one

SSL certificate monitoring best practices

Good certificate hygiene combines automated renewal with independent monitoring that confirms the renewal worked.

Monitoring

  • Monitor every public hostname, including subdomains and APIs, not just the main site
  • Check the certificate that is actually served, from outside your network
  • Set alert thresholds relative to your renewal automation: if certificates normally renew with a third of their lifetime left, an alert shortly after that point means automation has failed
  • Send alerts to a shared team channel rather than one person's inbox
  • Treat an unexpected change of issuer or expiry date as a signal to investigate

Renewal

  • Automate issuance and renewal with an ACME client such as Certbot or your hosting provider's built-in tooling
  • Make sure renewal also reloads or redeploys the certificate everywhere it is served
  • Keep an inventory of certificates, their owners and where each one is installed
  • Test renewal regularly, not only when a certificate is about to expire
  • Document the manual steps for any certificate that cannot be automated

SSL certificate types

Every certificate type expires and needs monitoring. They differ in what the certificate authority (CA) verifies and which names they cover.

  • Domain Validated (DV): proves control of the domain; the most common type, issued automatically by CAs such as Let's Encrypt
  • Organization Validated (OV): the CA also verifies the organisation behind the domain
  • Extended Validation (EV): stricter organisation checks; Chrome and Firefox stopped showing a special EV indicator in the address bar in 2019
  • Wildcard: covers all first-level subdomains, such as *.example.com, so one expiry affects every subdomain at once
  • Multi-domain (SAN): lists several hostnames in a single certificate

How to set up SSL certificate monitoring

You can set up SSL certificate monitoring in under an hour. Follow these steps.

  1. 1

    Inventory your certificates

    List every public hostname that serves HTTPS, including subdomains, APIs and any staging sites customers can reach. Note who owns each certificate and how it is renewed.

  2. 2

    Monitor each hostname

    Monitor the live certificate on every hostname so you see what visitors see. With nanokoi, SSL certificate monitoring is included on every plan, starting with the Free plan.

  3. 3

    Configure alerts

    Route alerts by email, Slack or webhook to people who can act on them, and choose thresholds that leave enough time to fix a failed renewal.

  4. 4

    Automate renewals

    Use an ACME client or your provider's automatic renewal so certificates are replaced without manual work, and let monitoring confirm that it worked.

  5. 5

    Test your configuration

    Run a periodic scan with the free Qualys SSL Labs server test to check the certificate chain, protocol versions and cipher suites.

Common SSL certificate mistakes

  • Relying on calendar reminders for certificates that now renew several times a year
  • Monitoring the main domain but forgetting www, API or regional subdomains
  • Assuming automation still works because it worked last time
  • Renewing the certificate but not reloading the web server or updating the CDN
  • Letting a wildcard certificate expire and taking every subdomain down at once
  • Serving a certificate without its intermediate chain

SSL certificate monitoring with nanokoi

nanokoi checks SSL certificates alongside uptime, so a certificate problem and an outage show up in the same place.

Included on every plan

SSL certificate monitoring is part of every plan, including the Free plan for up to 5 URLs. No credit card required.

Alerts where you work

Get alerts by email, Slack or webhook before an expiring certificate turns into a browser warning.

One account for all checks

Track certificates together with uptime, DNS monitoring and Google Lighthouse performance monitoring.

Export and API

Export monitoring data as CSV, JSON or XML, or pull it into your own tools with the REST API on paid plans.

SSL certificate monitoring FAQ

What is SSL certificate monitoring?

It is the automated checking of your website's TLS certificates for expiry, hostname coverage, chain problems and configuration issues, with alerts before visitors are affected.

How long are SSL certificates valid?

It depends on the issuer and the date of issue. Under CA/Browser Forum ballot SC-081v3, the maximum is 200 days for certificates issued from 15 March 2026, falling to 100 days in 2027 and 47 days in 2029. Let's Encrypt's default certificates are valid for 90 days, moving to 45 days by 2028.

Do I still need monitoring if my certificates renew automatically?

Yes. Automation can fail silently: a DNS or firewall change breaks validation, the server is not reloaded, or a CDN keeps serving the old certificate. Monitoring the live certificate is how you find out in time.

What happens when an SSL certificate expires?

Browsers show a full-page security warning instead of your site, and API clients and apps typically refuse to connect. For most visitors the site is effectively down until a valid certificate is installed.

Is SSL certificate monitoring free with nanokoi?

Yes. SSL certificate monitoring is included on the Free plan (up to 5 URLs, 5-minute checks) and on every paid plan.

Never miss an expiring certificate

Monitor SSL certificates and uptime together, with alerts by email, Slack or webhook. Start free with up to 5 URLs.

Register for free

No credit card required.

SSL certificate monitoring: prevent expiry outages