SSL monitoring

Certificates expire.Keep the date in view.

Checkmate reads the certificate your server presents and shows its expiry right on the monitor, with domain registration expiry alongside. When TLS breaks, the monitor goes down and alerts fire.

shop.example.comUp
HTTPS · checked every 60 s
Uptime / 30 days
99.98%
1 incident
Avg response
142 ms
p95 380 ms
Certificate expiry
84 days
Nov 23, 2026
Domain expiry
213 days
Mar 31, 2027
Response times
DayWeekMonth
00:0006:0012:0018:00Now
Recent checksTLS verified on every check
12:04:32200 OK138 ms
12:03:32200 OK129 ms
12:02:32200 OK151 ms
12:01:32200 OK144 ms
On the monitor

The expiry date, always in view.

Every HTTPS uptime monitor fetches the certificate your server presents and shows its expiry on the monitor page. There is no second product to configure and no separate list of hostnames to maintain.

Because the date comes from the live certificate, it shows the state your visitors get. A renewal that ran while the web server never reloaded shows up as a date that refused to move.

  • Expiry read from the certificate your server presents
  • Shown on every HTTPS monitor's detail page
  • Domain registration expiry tracked alongside
shop.example.comUp
HTTPS monitor
Certificate expiry
84 days
Nov 23, 2026
Domain expiry
213 days
Mar 31, 2027
Read from the certificate your server presents
Hard failures

When TLS breaks, alerts fire.

An expired or invalid certificate fails the HTTPS check itself. The monitor goes down, an incident opens and notifications go out on the channels attached to the monitor, the same path as any outage.

The failure message names the TLS error, so the alert that wakes you says certificate has expired instead of leaving you to diagnose a vague timeout.

  • Expired and invalid certificates fail the check
  • Down alerts on 12 notification channels
  • Per-monitor toggle to ignore TLS errors on staging
legacy.example.netDown
HTTPS · checked every 60 s
Last 40 checks
09:12:04certificate has expired
09:11:04certificate has expired
Down alerts fire on the monitor's notification channels
Domains too

Domain expiry, watched alongside.

Domains lapse the same way certificates do: quietly, then all at once. Checkmate also tracks domain registration expiry on uptime monitors, so the registration date and the certificate date live on the same page.

It is a small check that prevents a uniquely embarrassing outage.

  • Domain registration expiry on uptime monitors
  • Certificate and domain dates in one place
example.comUp
Certificate expiry
84 days
Nov 23, 2026
Domain registration
213 days
Mar 31, 2027
Both renewal dates on one monitor
Who runs this

For anyone who has renewed a certificate at 2am.

Agencies with client domains

Client sites live on HTTPS monitors anyway, and each monitor carries its certificate and domain dates. The renewal check rides along with the uptime check.

SaaS with customer domains

Custom customer domains multiply your certificate surface. Every domain you monitor shows its expiry date in the same place you already watch its uptime.

Self-hosters on Let's Encrypt

Automated renewal works until a cron job silently dies. The dashboard shows the date the renewal should have moved, and the checks fail loudly the moment it lapses.

Scope

What it covers, and what it doesn't.

Covered

  • Certificate expiry on HTTPS uptime monitors
  • Expiry date read from the live certificate, per monitor
  • Domain registration expiry tracked alongside
  • Failed TLS counts as downtime, with alerts on 12 channels
  • Per-monitor toggle to ignore TLS errors for staging hosts

Out of scope

  • Advance-expiry notifications: the dashboard shows the date and days remaining, alerts fire once TLS stops validating
  • TLS configuration grading: cipher suites and protocol audits are a job for a scanner like SSL Labs
  • Issuing or renewing certificates: that stays with your ACME tooling
Under the hood

For the technically curious.

Read from the live certificate

Expiry comes from the certificate your server presents, not from a registry lookup. If a renewal ran but the web server never reloaded, the monitor shows the certificate your visitors get.

Built for short-lived certificates

Let's Encrypt certificates renew every 90 days, so the date on the dashboard should move often. A date that stopped moving is the earliest sign a renewal job died quietly.

Internal hosts included

Because your instance runs the checks, hosts on internal networks are reachable too. Certificates on intranet services show the same expiry dates as public ones.

Hostnames stay private

A hosted certificate watcher learns your full domain inventory. Checkmate runs on your infrastructure, so the list of what you monitor never leaves it.

FAQ

Frequently askedquestions.

Certificate tracking is part of HTTPS uptime monitors. Checkmate reads the certificate your server presents, shows its expiry date on the monitor page and fails the check the moment the certificate stops validating.

It shows the expiry date and days remaining on every HTTPS monitor, and it alerts the moment a certificate stops validating. Scheduled advance-expiry warnings are not built yet, so the dashboard glance is the early check.

Yes. Short-lived certificates renew every 90 days, so the dashboard date should move often. A date that stalls means your renewal automation died, and an expiry that slips through fails the checks loudly.

Yes. The checks run from your own Checkmate instance, so anything your instance can reach, including intranet services, shows the same certificate dates as public sites.

No. Checkmate monitors, your ACME client or CA tooling renews. The separation is deliberate: the watcher stays independent of the automation it watches.

Yes. Uptime monitors track domain registration expiry alongside certificate expiry, so both renewal dates live on the same monitor page.

Checkmate is one. It is open source under AGPL-3.0, so you can self-host it and monitor as many certificates as you like with no per-domain pricing.

Get started

Every feature,no paywall.

Checkmate is open source under AGPL-3.0. Self-host it and this feature ships free, on your servers, with your data.