SignalWatch (opens in a new tab) 4 min read
How to monitor TLS certificate expiry
A certificate that expires takes the site down for anyone who trusts the browser warning. Watch the public URL and get an alert inside 14 days, then again at 3.
Watch the certificate on the public URL you already care about. SignalWatch (opens in a new tab) alerts when that certificate is inside 14 days of expiry, and again when it is inside 3 days. You do not set up a second product for TLS. The page monitor includes it.
What actually happens when a certificate expires
Browsers stop treating the site as safe. Visitors see a full-page warning. APIs that verify TLS fail. A checkout, a login, and a webhook receiver can all go quiet at once, including ones you forgot were on that host.
Renewal is usually automatic: a host or a proxy requests a new certificate before the old one lapses. Automatic renewal fails in ordinary ways. The DNS record moved, the HTTP challenge path was blocked, the account that owns the certificate was not the account you thought, or the certificate was uploaded by hand a year ago and nobody put a reminder anywhere.
The expiry date is the last moment, not the first moment you should hear about it. Fourteen days is enough time to renew on a normal week. Three days is the "this is still not done" ping.
What to point the monitor at
Use the hostname people type.
https://example.com/andhttps://www.example.com/can be different certificates. Monitor the one that is public, or both if both answer.- A marketing site and an app subdomain often have separate certificates. A green padlock on the homepage says nothing about
app.orapi.. - The check reads the certificate presented to a normal HTTPS request. It does not log into your hosting account, and it does not renew anything.
If you already monitor that URL for text changes, TLS rides along. The setup for text, selectors, and webhooks is in how to get alerted when a web page changes.
How the alert fits the other checks
One SignalWatch monitor on a public URL can tell you three things:
- Visible text changed, with a unified diff.
- The URL went down, and when it came back.
- The certificate is inside 14 days, then again inside 3 days.
Alerts can go to email, Slack, Discord, or an HMAC-signed JSON webhook. Free plan: 3 monitors, checks every 15 minutes, no card. A certificate does not move every 15 minutes. The short interval matters more for downtime and for text. The expiry alerts are date-based: 14 days, then 3.
Pro ($12/month or $79/year) raises the cap to 50 monitors and checks every 5 minutes. Business ($29/month or $199/year) is 500 monitors and every 2 minutes. You do not need the faster plans just to hear about a certificate. You need them when you also want tighter downtime checks, or when 3 URLs is not enough.
What to do when it fires
- Open the host that issued the certificate. That is the place renewal has to succeed: the server, the load balancer, or the host's certificate screen.
- Confirm the date. The alert means "inside 14 days" or "inside 3 days", not "already expired".
- Renew, or fix the automation that should have renewed.
- Load the public URL and read the new expiry. The next check should see the new certificate.
- If you have a second hostname, check that one too. Renewing
wwwdoes not renewapiunless they share a certificate.
Write down which hostnames are monitored. A spreadsheet of expiry dates goes stale. A monitor on the URL does not.
What this does not replace
It does not replace a host's own renewal logs. If the challenge is failing every night and the certificate is still 40 days out, SignalWatch will stay quiet, correctly, until the 14-day mark. Look at the renewal job if you want earlier warning of a broken pipeline.
It does not crawl your site for broken links. After a certificate incident, links are a separate question. Mortise (opens in a new tab) is the tool that alerts when a previously working link newly breaks. When to use which is in website change monitoring vs broken-link monitoring.
Checklist
- Every public hostname that would hurt if it warned visitors, listed as its own URL.
- The monitor left in place after renewal, so the next cycle is covered.
- Alert destination that a person sees. A webhook nobody reads is not a reminder.
- Fourteen days treated as the work window. Three days treated as late.