What we watch

TLS certificate.

Certificates now renew on a short cycle, usually automatically. That works until the day it does not, and the failure is visible to every visitor.

What we check

  • Expiry date and days remaining
  • The issuing authority, and any change to it
  • Which names the certificate actually covers, including subdomains you may have added since
  • The full chain of trust, since an incomplete chain fails for some visitors and works for others
  • Whether the certificate presented matches the site that is being served

The automation problem

Most certificates renew themselves now, which has removed the majority of these failures and created a new one. Because it works silently for years, nobody notices when the renewal job stops running, and there is often no longer anyone who remembers how it was set up.

The common causes are a renewal process on a server that was migrated, a certificate covering a name that was later removed from the configuration, and a manual certificate somebody issued for a single subdomain and forgot.

When you hear from us

Immediately at thirty, fourteen and seven days, then daily inside the final week. Immediately if the issuer changes unexpectedly, if the chain becomes incomplete, or if the certificate stops covering a name it covered before.

What ends up in the record

Every certificate ever issued for the domain while we have watched it, with issue and expiry dates and issuer. That lineage is useful during audits and security reviews, where the question is not what is installed today but what has been installed over time.

More on ACME and where renewals actually live: automated certificates.

Check yours

Look up your certificate.

Issuer, expiry, covered names and chain of trust. Free and instant.