GuideSSL / TLS monitoring
SSL monitoring, explained
A certificate that expires, loses a link in its chain, or stops matching a hostname takes a site down while an uptime check still reads 200 OK. These guides cover what SSL monitoring actually watches, and why it has to read the certificate the server serves rather than a copy on disk.
What is SSL monitoring?SSL monitoring watches the certificate a server actually serves and warns before it expires or breaks. What it checks, and why an uptime ping is not enough.
SSL certificate expiry: what to watch, and whenCertificates expire, and validity windows are shrinking fast. What to watch, when to be alerted, and why the leaf date is only part of the story.
Certificate chain validation: leaf, intermediate, rootYour leaf certificate can be valid while the chain above it is broken. How chain validation works, and why an intermediate expiry causes silent outages.
Monitoring Let's Encrypt certificatesLet's Encrypt certificates auto-renew every 90 days — until one does not. What to monitor when most of your certificates renew themselves.
Certificate Transparency log monitoringCertificate Transparency logs record every publicly trusted certificate. Monitoring them flags a new certificate for your domain, even ones you did not request.
Monitoring wildcard and SAN certificatesOne wildcard or SAN certificate can cover many hostnames. What to monitor when a single certificate secures a whole set of subdomains.
Choosing a tool? Compare the best SSL monitoring tools.
Stop watching certificates by hand
CertPost reads the served certificate on a schedule — chain, hostname, expiry, Certificate Transparency, and the domain around it — and warns you before a certificate takes a site down. Three certificates free, forever.
Start monitoring free