What we check
- Expiry date and days remaining
- The issuing authority, and any change to it
- Which names the certificate actually covers, including subdomains you may have added since
- The full chain of trust, since an incomplete chain fails for some visitors and works for others
- Whether the certificate presented matches the site that is being served
The automation problem
Most certificates renew themselves now, which has removed the majority of these failures and created a new one. Because it works silently for years, nobody notices when the renewal job stops running, and there is often no longer anyone who remembers how it was set up.
The common causes are a renewal process on a server that was migrated, a certificate covering a name that was later removed from the configuration, and a manual certificate somebody issued for a single subdomain and forgot.
When you hear from us
Immediately at thirty, fourteen and seven days, then daily inside the final week. Immediately if the issuer changes unexpectedly, if the chain becomes incomplete, or if the certificate stops covering a name it covered before.
What ends up in the record
Every certificate ever issued for the domain while we have watched it, with issue and expiry dates and issuer. That lineage is useful during audits and security reviews, where the question is not what is installed today but what has been installed over time.