AgenciesCare plans, MSPs, client fleets

Every client certificate, watched from outside

Your care plan promises the client’s site stays secure and online. A certificate that expires — or renews on disk while the server keeps serving the old one — breaks that promise before anyone’s tooling notices. CertPost is client website monitoring for the certificate layer: it reads what each client’s visitors actually receive, grades it, and alerts you while there’s still time to fix it quietly. Try any client’s site now:

Free instant check. No signup, no email, no crawler — we read the certificate your server presents to real visitors.

The failure mode care plans miss

Renewal automation fails silently. Certbot writes a fresh certificate and exits zero — and nginx keeps serving the old one because nothing reloaded it. The cron mails its errors to a root mailbox nobody reads. A DNS record gets cleaned up and the challenge quietly stops validating. Every log on the box says fine; the first external signal is a browser warning — on your client’s site, found by your client. Watching from outside is the only vantage point that catches all of these, because it checks the one thing that matters: what the site serves right now.

Paste your whole client list

Domains, URLs or host:port, one per line or comma-separated. Every site is checked the second you add it — a fifty-client book is set up in one paste.

One board, graded A–F

Expiry, chain including intermediates, hostname coverage, TLS configuration, security headers, email auth and DNS security — per client, at a glance, with the sites needing attention first.

Alerts before the client calls

Email and webhooks, fired on expiry lead-time and on grade drops — so a config regression on a client site reaches you as a task, not as an angry phone call.

Flat pricing that fits a book of clients

Team — $29/month

  • Unlimited certificates
  • Checks every hour
  • Up to 5 team members
  • Certificate Transparency alerts
  • Reputation & threat intelligence

Agency — $79/month

  • Everything in Team
  • Checks every 15 minutes
  • Public status pages for clients
  • Priority support

No per-domain pricing: the incumbent tools charge by certificate, which is exactly what makes them awkward inside a care plan. Full details on the pricing page.

Questions agencies ask

Do you charge per client site?

No. Team is $29/month for unlimited certificates, and Agency is $79/month with checks every 15 minutes. Your fiftieth client site costs the same as your first — which is the point of putting certificate monitoring inside a care plan instead of pricing it per domain.

Do I need access to my clients’ servers?

No. Checks run from outside, against the certificate each site actually serves on a live TLS connection. No agent, no DNS change, no client credentials — you can add a site you don’t host at all.

Our uptime monitor already has an SSL checkbox. Why this?

An uptime checkbox tells you the site was up and the certificate hadn’t expired yet. It doesn’t validate the chain including intermediates, grade the TLS configuration, or catch the classic silent failure: the renewal succeeded on disk but the server was never reloaded and keeps serving the old certificate. CertPost reads what the client’s visitors actually receive, so that failure is visible weeks before it becomes an outage.

Can it watch things that aren’t websites?

Yes, any TLS service on any port using host:port syntax — including implicit-TLS mail and directory ports like 465, 993 and 636. STARTTLS ports such as 587 are not supported.

Three client sites free, no card

Start with your three riskiest clients. If the board is useful, paste the rest of the book.

Watch your client sites