What we checkCertificate & HTTPSTL-03
Certificate expiry
We warn as the certificate approaches its expiry date, and alert monitored domains at 30, 14, 7 and 1 days.
- Check
- TL-03
- Included
- Free in every scan
What we check
We read notAfter from the leaf certificate and count the days remaining.
Why it matters
Certificate expiry is one of the few outages you can see coming weeks ahead, and one of the most common ones that still happens.
The usual cause is not forgetting — it is an automatic renewal that stopped working months ago and looks identical to one that is working, right up until the day it does not.
There is no partial failure and no warning to visitors beforehand. The certificate is valid, and then a second later every browser refuses the connection — which is why this is worth watching rather than checking occasionally.
How to fix it
- 1
Renew it.
- 2
If renewal is automated, check the job actually ran recently rather than assuming it will.
- 3
Add the domain to monitoring so you are told at 30 days, not on the morning it expires.
Common questions
- Let's Encrypt renews automatically. Why warn me?
- Because a silent failure in that automation is exactly what this catches. A renewal that has not run for two months looks like a working one until the certificate is 30 days out.
- How long should certificates last?
- 90 days is the modern norm and it is a feature: a short life forces the automation to be real and exercised, rather than something someone does by hand once a year.
- When do you send the alerts?
- At 30, 14, 7 and 1 days remaining, once each, to monitored domains.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.