Monitoring

Monitor SSL certificates before they expire

Expired certificates are the most embarrassing avoidable outage: the browser shows a red warning, the client calls, and auto-renewal had been broken for weeks. DomainWarn checks every certificate of your client domains every six hours and alerts you in time.

Every feature, no credit card, cancel monthly.

  • Hosted in Germany
  • GDPR compliant, DPA on request
  • Proper VAT invoice
  • Cancel monthly

What the alerts look like

  • Certificate of www.client.com expires in 14 days (Let's Encrypt, valid until 2026-09-26)
  • Certificate of shop.client.com renewed: new serial, valid until 2026-12-10
  • Chain of api.client.com incomplete: intermediate certificate missing
  • Certificate of mail.client.com:993 expired, IMAP clients show warnings
  • Host name mismatch: certificate of client.com only covers www.client.com

Why auto-renewal is not enough

Let's Encrypt and 90-day lifetimes made renewal routine, and that is exactly why nobody looks any more. It still fails regularly: a changed DNS record, a firewall blocking port 80, an expired API key, a migration that left the cron job behind. The error then sits in a log for weeks until the old certificate expires.

DomainWarn does not check whether renewal runs but what is actually served: the certificate the browser sees, with remaining lifetime, chain and host names.

What is monitored

  • Remaining lifetime: notice 30 days ahead, warning 14 days ahead, critical on expiry.
  • Chain: missing intermediates that work on the developer's machine and fail on Android devices.
  • Host name and alternative names: certificate does not match the requested name.
  • Renewal: a certificate change is reported as information so you know the automation works.
  • TLS version and issuer, including self-signed certificates on staging systems.
  • Mail servers: SMTP, IMAP and POP3 via STARTTLS or implicit TLS, whose expiry no browser reports.

HTTP check included

Alongside the certificate DomainWarn checks the website itself: does it respond, with which status code, how fast, does the redirect from http to https stay intact, is HSTS set. If the site goes down an incident is created; when it comes back, exactly one all-clear. No server agent, nothing to install at the client.

Compared to uptime tools

Uptime services report an expired certificate, which is too late. Some warn beforehand but only check port 443 and not the chain. DomainWarn is built to keep a hundred client domains including mail servers in one overview and to catch the certificates nobody else watches: subdomains, staging, API, mail.

Frequently asked questions

How often is it checked?
Certificates every six hours, HTTP availability in the interval of the plan: every minute on Agency, every five minutes on Freelancer.
Which ports are checked?
443 by default. Mail servers can additionally be monitored on 25, 465, 587, 143, 993, 110 and 995.
Does DomainWarn report renewals too?
Yes, as information: a new certificate with a new serial and expiry date is mentioned in the daily digest, without an alarm.

Who DomainWarn is for

Web agencies, freelancers, web developers and IT service providers who look after many client domains and want to know when a client switches hosting, someone breaks the SPF record or a certificate expires. No server monitoring, no agents, no configuration at the client.

Try 14 days for free

More monitoring topics: DNS monitoring · Email monitoring · Domain monitoring