SSL and domain expiry

Know before a certificate or a domain runs out

An expired certificate turns a working site into a browser warning, and an expired domain takes the site, the email and every link to it down at once. Both are dated months in advance. UptimeWarrior reads the dates and reminds you in steps, so the renewal happens while it is still routine.

Certificate

Read hourly on every plan. Reminders at 14, 7, 3 and 1 days left.

Domain

Read from the registry every 6h, on Pro and up. Reminders at 30, 14, 7, 3 and 1 days left.

Nothing to install

Both are read from outside, the way a browser and a registrar see them.

01 / how

What is read, and when you hear about it

TLS certificate

hourly

The certificate is opened twice: once without verification, to read the expiry date even on a chain nobody trusts, and once with it, to find out whether a browser would object. A reminder goes out at 14, 7, 3 and 1 days left. A certificate a browser would not trust fails the uptime check, and is confirmed and announced as an outage.

Domain expiry

every 6h

A lookup against the registry for the registrable domain (RDAP first, WHOIS behind it) for the registrar and the renewal date. A reminder goes out at 30, 14, 7, 3 and 1 days left. Where a registry publishes no expiry date, .nl and .de among them, the dashboard says so rather than leaving a blank. On by default for a new site, on Pro and up.

Where the dates show

always

On the dashboard, with the days left; on the site's public status page, so a client can see the dates without asking (the domain's on Pro and up); and in the weekly report on Pro and up.

The uptime check, the broken link scan and the meta tag scan run on the same sites. Everything that is checked.

questions

Questions

How far ahead do I hear about an expiring certificate?

At 14, 7, 3 and 1 days before it expires, by email and through any webhook you have added.

The certificate is read hourly, so a renewed certificate replaces the old date at the next read and nothing further is sent about the old one.

Does it work with Let's Encrypt and other certificates that renew every few months?

Yes. It reads whichever certificate the server presents, from any issuer. A certificate that renews on schedule shows its new expiry date after the next read; one that fails to renew reaches the reminders like any other.

What happens if the certificate is invalid rather than expiring?

A certificate a browser would not trust makes the uptime check fail, and it is handled as an outage: asked again 30 seconds later and announced only if it fails again.

Which domains can't be checked for expiry?

Those whose registry publishes no expiry date, .nl and .de among them. The dashboard says so for those domains rather than showing a blank.

The lookup asks the registry over RDAP first and falls back to WHOIS, which covers registries that publish a date in only one of them.

Is domain expiry on every plan?

No, it starts on Pro. Certificate expiry is on every plan.

Read next

  • Monitoring for agencies

    Monitoring every client site on any stack, with each client's status page, report and alerts kept to that client, billed per site rather than per seat.

  • Broken links and meta tags

    What the scheduled scan of the page you monitor reads (dead links, title, description, social image, viewport and charset) and what it does not do.

  • Status pages

    A public page per site, or per client, showing whether it is up, the last week of checks and when the certificate runs out.

  • Weekly client reports

    The weekly PDF of uptime, response times, certificates, domains and page issues, and the per-client version that covers only that client's sites.

  • Pricing

    What a month costs at 1, 5, 11, 25 and 50 sites, and how the bill is put together.

See it on a site you know

Run one check now without an account, or make one and leave it watching. Free covers 3 sites, takes no card and keeps running for as long as somebody signs in.