Oh Dear alternative

Priced per site, or priced per nothing: the certificate math against Oh Dear

Verified 24 Jul 2026

Oh Dear is a well-built site-health suite — uptime, SSL, broken links, mixed content, cron monitoring — and if you want all of that per site, it is a fair choice. This page is about the certificate half of the story, where the economics and the coverage work differently. The pricing shape. Oh Dear bundles everything per site: plans start around €15/month for a small bundle and grow with your site count (about $49/month at 50 sites). There is a 10-day trial, but no free tier. CertPost prices the other way: certificates are the product, and the count barely matters — 3 free forever, up to 100 for a flat $9/month, unlimited on Team at $29. An agency with 60 client domains is comparing roughly $49+/month against $9–29 flat. The coverage shape. Oh Dear watches websites, and does it well. But certificates do not only live on websites: • Mail servers — SMTP on 465/587, IMAPS on 993 — carry their own certificates, expire on their own schedule, and fail quietly because mail clients rarely complain loudly. • Admin panels and internal services on ports like 8443. • LDAPS, database TLS, anything else that answers a handshake. CertPost checks any host:port that speaks TLS, over IPv4 and IPv6, and validates what is actually served: the full chain including intermediates, hostname and SAN match, and fingerprint changes — plus Certificate Transparency issuance alerts, domain registration expiry, and DNS record drift. And around the certificate, every CertPost check grades the security posture browsers and auditors see: TLS configuration, security headers, email authentication (SPF, DKIM, DMARC), DNS security (DNSSEC, CAA, dangling CNAMEs), and threat-intel reputation — A to F, with a plain-English finding behind every deduction. If you run Oh Dear and like it for uptime and site health, there is no need to rip it out. The question this page answers is narrower: when the thing you need watched is every certificate you are responsible for — including the ones not attached to a website — a dedicated monitor covers more of them for less. Start with the free instant check on the homepage: paste any domain and see the full report, no signup.
The switch (or the pairing) in five minutes: 1. Sign up free — no card, 3 certificates forever. 2. Paste every hostname you terminate TLS on — not just the websites. Apex, www, API, mail hosts with ports (mail.example.com:465, imap.example.com:993), admin panels on 8443. One per line. 3. The dashboard sorts by urgency; anything red or amber gets fixed today. 4. Point alerts where your team lives: email, Slack, Discord, or a webhook. 5. Hosts on working auto-renew get "auto-renew expected" — quiet until 7 days out or a real failure. If you monitor more than 3 certificates, Personal is $9/month flat up to 100. Agencies with many client domains: Team is $29/month, unlimited certificates, 5 seats — the per-site math never enters into it.

Import your domain list in 2 minutes — 3 certificates free, no card.

Start free