Why SSL certificates matter
A certificate proves that visitors are talking to your real server and encrypts everything they send. When it expires or fails validation, browsers show a full-page security warning, and APIs and mobile apps usually refuse to connect at all.
Security
- Encrypts data in transit between visitors and your server
- Protects logins, form submissions and payment details
- Proves the server's identity, which prevents man-in-the-middle attacks
- Ensures data is not altered on the way
Search and user trust
- Google has used HTTPS as a ranking signal since 2014 (Google Search Central, 2014)
- Major browsers label plain HTTP pages as "Not secure"
- Certificate errors stop visitors on a warning page before your site loads
- Browser features such as service workers and HTTP/2 require HTTPS
Why certificate lifetimes are getting shorter
Certificate lifetimes are being cut in stages. In April 2025 the CA/Browser Forum approved ballot SC-081v3, which lowers the maximum validity of publicly trusted TLS certificates (CA/Browser Forum, 2025):
- 200 days for certificates issued from 15 March 2026
- 100 days for certificates issued from 15 March 2027
- 47 days for certificates issued from 15 March 2029
Let's Encrypt, whose default certificates are valid for 90 days, plans to move to 45 days by February 2028 (Let's Encrypt, 2025). Shorter lifetimes mean more renewals per year, and every renewal is a chance for automation to fail quietly. That makes monitoring more important, not less.
Certificate lifecycle
What to check beyond the expiry date
Expiry is the most common failure, but not the only one. A useful SSL certificate monitoring setup watches for these problems:
Common SSL certificate problems
- Expiry: the certificate's end date, compared with your renewal schedule
- Hostname mismatch: the certificate does not cover the name being visited, for example www versus the bare domain
- Incomplete chain: a missing intermediate certificate, which some browsers and most API clients reject
- Untrusted or revoked certificates: self-signed certificates in production, or certificates revoked by the issuing CA
- Weak configuration: deprecated protocol versions such as TLS 1.0 and 1.1, or weak keys and cipher suites
- Renewal that never deployed: a new certificate was issued, but the server, load balancer or CDN still serves the old one
SSL certificate monitoring best practices
Good certificate hygiene combines automated renewal with independent monitoring that confirms the renewal worked.
Monitoring
- Monitor every public hostname, including subdomains and APIs, not just the main site
- Check the certificate that is actually served, from outside your network
- Set alert thresholds relative to your renewal automation: if certificates normally renew with a third of their lifetime left, an alert shortly after that point means automation has failed
- Send alerts to a shared team channel rather than one person's inbox
- Treat an unexpected change of issuer or expiry date as a signal to investigate
Renewal
- Automate issuance and renewal with an ACME client such as Certbot or your hosting provider's built-in tooling
- Make sure renewal also reloads or redeploys the certificate everywhere it is served
- Keep an inventory of certificates, their owners and where each one is installed
- Test renewal regularly, not only when a certificate is about to expire
- Document the manual steps for any certificate that cannot be automated
SSL certificate types
Every certificate type expires and needs monitoring. They differ in what the certificate authority (CA) verifies and which names they cover.
- Domain Validated (DV): proves control of the domain; the most common type, issued automatically by CAs such as Let's Encrypt
- Organization Validated (OV): the CA also verifies the organisation behind the domain
- Extended Validation (EV): stricter organisation checks; Chrome and Firefox stopped showing a special EV indicator in the address bar in 2019
- Wildcard: covers all first-level subdomains, such as *.example.com, so one expiry affects every subdomain at once
- Multi-domain (SAN): lists several hostnames in a single certificate
How to set up SSL certificate monitoring
You can set up SSL certificate monitoring in under an hour. Follow these steps.
- 1
Inventory your certificates
List every public hostname that serves HTTPS, including subdomains, APIs and any staging sites customers can reach. Note who owns each certificate and how it is renewed.
- 2
Monitor each hostname
Monitor the live certificate on every hostname so you see what visitors see. With nanokoi, SSL certificate monitoring is included on every plan, starting with the Free plan.
- 3
Configure alerts
Route alerts by email, Slack or webhook to people who can act on them, and choose thresholds that leave enough time to fix a failed renewal.
- 4
Automate renewals
Use an ACME client or your provider's automatic renewal so certificates are replaced without manual work, and let monitoring confirm that it worked.
- 5
Test your configuration
Run a periodic scan with the free Qualys SSL Labs server test to check the certificate chain, protocol versions and cipher suites.
Common SSL certificate mistakes
- Relying on calendar reminders for certificates that now renew several times a year
- Monitoring the main domain but forgetting www, API or regional subdomains
- Assuming automation still works because it worked last time
- Renewing the certificate but not reloading the web server or updating the CDN
- Letting a wildcard certificate expire and taking every subdomain down at once
- Serving a certificate without its intermediate chain
SSL certificate monitoring with nanokoi
nanokoi checks SSL certificates alongside uptime, so a certificate problem and an outage show up in the same place.
Included on every plan
SSL certificate monitoring is part of every plan, including the Free plan for up to 5 URLs. No credit card required.
Alerts where you work
Get alerts by email, Slack or webhook before an expiring certificate turns into a browser warning.
One account for all checks
Track certificates together with uptime, DNS monitoring and Google Lighthouse performance monitoring.
Export and API
Export monitoring data as CSV, JSON or XML, or pull it into your own tools with the REST API on paid plans.
SSL certificate monitoring FAQ
What is SSL certificate monitoring?
It is the automated checking of your website's TLS certificates for expiry, hostname coverage, chain problems and configuration issues, with alerts before visitors are affected.
How long are SSL certificates valid?
It depends on the issuer and the date of issue. Under CA/Browser Forum ballot SC-081v3, the maximum is 200 days for certificates issued from 15 March 2026, falling to 100 days in 2027 and 47 days in 2029. Let's Encrypt's default certificates are valid for 90 days, moving to 45 days by 2028.
Do I still need monitoring if my certificates renew automatically?
Yes. Automation can fail silently: a DNS or firewall change breaks validation, the server is not reloaded, or a CDN keeps serving the old certificate. Monitoring the live certificate is how you find out in time.
What happens when an SSL certificate expires?
Browsers show a full-page security warning instead of your site, and API clients and apps typically refuse to connect. For most visitors the site is effectively down until a valid certificate is installed.
Is SSL certificate monitoring free with nanokoi?
Yes. SSL certificate monitoring is included on the Free plan (up to 5 URLs, 5-minute checks) and on every paid plan.
Never miss an expiring certificate
Monitor SSL certificates and uptime together, with alerts by email, Slack or webhook. Start free with up to 5 URLs.
Register for freeNo credit card required.