Skip to content

What we checkCertificate & HTTPSTL-03

Certificate expiry

We warn as the certificate approaches its expiry date, and alert monitored domains at 30, 14, 7 and 1 days.

Check
TL-03
Included
Free in every scan

What we check

We read notAfter from the leaf certificate and count the days remaining.

Why it matters

Certificate expiry is one of the few outages you can see coming weeks ahead, and one of the most common ones that still happens.

The usual cause is not forgetting — it is an automatic renewal that stopped working months ago and looks identical to one that is working, right up until the day it does not.

There is no partial failure and no warning to visitors beforehand. The certificate is valid, and then a second later every browser refuses the connection — which is why this is worth watching rather than checking occasionally.

How to fix it

  1. 1

    Renew it.

  2. 2

    If renewal is automated, check the job actually ran recently rather than assuming it will.

  3. 3

    Add the domain to monitoring so you are told at 30 days, not on the morning it expires.

Common questions

Let's Encrypt renews automatically. Why warn me?
Because a silent failure in that automation is exactly what this catches. A renewal that has not run for two months looks like a working one until the certificate is 30 days out.
How long should certificates last?
90 days is the modern norm and it is a feature: a short life forces the automation to be real and exercised, rather than something someone does by hand once a year.
When do you send the alerts?
At 30, 14, 7 and 1 days remaining, once each, to monitored domains.

See how your domain does on this check.

All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.