Checkmate reads the certificate your server presents and shows its expiry right on the monitor, with domain registration expiry alongside. When TLS breaks, the monitor goes down and alerts fire.
Every HTTPS uptime monitor fetches the certificate your server presents and shows its expiry on the monitor page. There is no second product to configure and no separate list of hostnames to maintain.
Because the date comes from the live certificate, it shows the state your visitors get. A renewal that ran while the web server never reloaded shows up as a date that refused to move.
An expired or invalid certificate fails the HTTPS check itself. The monitor goes down, an incident opens and notifications go out on the channels attached to the monitor, the same path as any outage.
The failure message names the TLS error, so the alert that wakes you says certificate has expired instead of leaving you to diagnose a vague timeout.
Domains lapse the same way certificates do: quietly, then all at once. Checkmate also tracks domain registration expiry on uptime monitors, so the registration date and the certificate date live on the same page.
It is a small check that prevents a uniquely embarrassing outage.
Client sites live on HTTPS monitors anyway, and each monitor carries its certificate and domain dates. The renewal check rides along with the uptime check.
Custom customer domains multiply your certificate surface. Every domain you monitor shows its expiry date in the same place you already watch its uptime.
Automated renewal works until a cron job silently dies. The dashboard shows the date the renewal should have moved, and the checks fail loudly the moment it lapses.
Expiry comes from the certificate your server presents, not from a registry lookup. If a renewal ran but the web server never reloaded, the monitor shows the certificate your visitors get.
Let's Encrypt certificates renew every 90 days, so the date on the dashboard should move often. A date that stopped moving is the earliest sign a renewal job died quietly.
Because your instance runs the checks, hosts on internal networks are reachable too. Certificates on intranet services show the same expiry dates as public ones.
A hosted certificate watcher learns your full domain inventory. Checkmate runs on your infrastructure, so the list of what you monitor never leaves it.
Certificate tracking is part of HTTPS uptime monitors. Checkmate reads the certificate your server presents, shows its expiry date on the monitor page and fails the check the moment the certificate stops validating.
It shows the expiry date and days remaining on every HTTPS monitor, and it alerts the moment a certificate stops validating. Scheduled advance-expiry warnings are not built yet, so the dashboard glance is the early check.
Yes. Short-lived certificates renew every 90 days, so the dashboard date should move often. A date that stalls means your renewal automation died, and an expiry that slips through fails the checks loudly.
Yes. The checks run from your own Checkmate instance, so anything your instance can reach, including intranet services, shows the same certificate dates as public sites.
No. Checkmate monitors, your ACME client or CA tooling renews. The separation is deliberate: the watcher stays independent of the automation it watches.
Yes. Uptime monitors track domain registration expiry alongside certificate expiry, so both renewal dates live on the same monitor page.
Checkmate is one. It is open source under AGPL-3.0, so you can self-host it and monitor as many certificates as you like with no per-domain pricing.
Websites and APIs checked from 6 continents.
ICMP reachability for anything with an IP.
Databases, mail and SSH watched at the socket.
Records resolved against the resolver you choose.
Handshake checks for ws:// and wss:// endpoints.
The standard health protocol, checked on schedule.
More than 100 game types over native protocols.
CPU, memory, disk and network via the Capture agent.
Container status, health checks and resource usage.
Lighthouse scores and Core Web Vitals on a schedule.
Branded public pages served from your own instance.
12 native channels, from email to PagerDuty.
Every outage recorded, resolved and explained.
All featuresCheckmate is open source under AGPL-3.0. Self-host it and this feature ships free, on your servers, with your data.