SSL monitoring

Certificates expire.Surprises are optional.

Checkmate reads the certificate your server presents, warns you ahead of expiry and shows the details right on the monitor. Renewal stays your job, remembering stops being one.

shop.example.comCertificate valid
checked hourly
Expires in
84 days
Nov 23, 2026
Issuer
Let's Encrypt
R11
Domain expiry
213 days
Mar 31, 2027
Certificate
SubjectCN=shop.example.com
Valid fromAug 25, 2026
Valid toNov 23, 2026
Early warnings

Expiry warnings before browsers complain.

An expired certificate greets your visitors with a full-page security warning, and most of them leave. Checkmate tracks expiry for the certificates behind your HTTPS monitors and warns you while there is still time to renew calmly.

The warning arrives on the channels you already use: email, Slack, PagerDuty or any of the 12 supported channels.

  • Expiry detection with early warnings
  • Alerts on 12 notification channels
  • Certificate details on the monitor page
#opsSlack
CCheckmateAPP · 09:12
Certificate for shop.example.com expires in 14 days (Nov 23).
Expiry warning
Also sent to: email · PagerDuty
One dashboard

Built into every monitor you add.

Certificate tracking is built into HTTPS uptime monitors, so there is no second product to configure and no second list of hostnames to maintain. Add a monitor for an endpoint and its certificate is watched from that moment on.

Fleets with many domains get one sortable view of what expires when, instead of a spreadsheet someone forgets to update.

  • Automatic for HTTPS uptime monitors
  • Expiry visible across the whole fleet
  • No separate certificate inventory to maintain
Certificatessorted by expiry
api.example.com84 days
shop.example.com14 days
legacy.example.net3 days
docs.example.com61 days
Domains too

Domain expiry, watched alongside.

Domains lapse the same way certificates do: quietly, then all at once. Checkmate also tracks domain registration expiry on uptime monitors, so the registration renewal and the certificate renewal live on the same page.

It is a small check that prevents a uniquely embarrassing outage.

  • Domain registration expiry on uptime monitors
  • Certificate and domain dates in one place
example.comUp
Certificate expiry
84 days
Nov 23, 2026
Domain registration
213 days
Mar 31, 2027
Both renewal dates on one monitor
Who runs this

For anyone who has renewed a certificate at 2am.

Agencies with client domains

Dozens of client sites means dozens of renewal dates. One dashboard shows what expires next across the whole book of clients.

SaaS with customer domains

Custom customer domains multiply your certificate surface. Watch them all without adding each to a calendar by hand.

Self-hosters on Let's Encrypt

Automated renewal works until a cron job silently dies. An independent expiry check catches the failure weeks before the deadline.

Scope

What it covers, and what it doesn't.

Covered

  • Certificate expiry for HTTPS uptime monitors
  • Early warnings ahead of the expiry date
  • Certificate details on the monitor page
  • Domain registration expiry tracked alongside
  • Alerts on 12 notification channels

Out of scope

  • TLS configuration grading: cipher suites and protocol audits are a job for a scanner like SSL Labs
  • Certificate transparency log monitoring
  • Issuing or renewing certificates: that stays with your ACME tooling
Under the hood

For the technically curious.

Read from the live certificate

Expiry comes from the certificate your server presents during checks, not from a registry lookup. If a renewal ran but the web server never reloaded, the monitor shows the certificate your visitors get.

Built for short-lived certificates

Let's Encrypt certificates renew every 90 days, which means more renewals and more chances for automation to fail quietly. An independent watcher that pages you on a missed renewal is the safety net.

Internal hosts included

Because your instance runs the checks, hosts on internal networks are reachable too. Certificates on intranet services get the same expiry warnings as public ones.

Hostnames stay private

A hosted certificate watcher learns your full domain inventory. Checkmate runs on your infrastructure, so the list of what you monitor never leaves it.

FAQ

Frequently askedquestions.

Certificate tracking is part of HTTPS uptime monitors. Checkmate reads the certificate your server presents during checks, shows its expiry on the monitor page and warns you ahead of the date on your notification channels.

Yes, and it is a good match: short-lived certificates renew often, so automation has more chances to fail quietly. Checkmate acts as the independent check that notices a missed renewal before the certificate lapses.

Yes. The checks run from your own Checkmate instance, so anything your instance can reach, including intranet services, gets the same certificate monitoring as public sites.

No. Checkmate monitors and alerts, your ACME client or CA tooling renews. The separation is deliberate: the watcher stays independent of the automation it watches.

Yes. Uptime monitors track domain registration expiry alongside certificate expiry, so both renewal dates live on the same monitor page.

Checkmate is one. It is open source under AGPL-3.0, so you can self-host it and monitor as many certificates as you like with no per-domain pricing.

Get started

Every feature,no paywall.

Checkmate is open source under AGPL-3.0. Self-host it and this feature ships free, on your servers, with your data.