SSL monitoring watches your hosts’ TLS certificates and emails you before they expire — the outage you only notice when customers do. Available on paid plans (see quotas); extra monitors come in +50 blocks as an add-on.
Add a monitor
On Dashboard → SSL monitors, enter the host and click Add monitor:
example.com— checks port 443example.com:8443— a non-standard HTTPS port works too
Anything with a TLS certificate a public probe can reach is fair game: websites, APIs, mail hosts on their TLS ports. Monitored hosts (and alternate emails) are encrypted at rest.
Warning thresholds
Pick when to be warned: 30, 14, 7, 3 and 1 days before expiry (all on by default). We check each certificate at least daily, and you get one email per threshold crossing — not a daily nag. Thresholds are editable per monitor, inline, at any time.
Alternate recipients
Each monitor can CC up to 5 extra addresses (comma-separated) — your ops list, an on-call alias, a client. They receive the same threshold alerts as your account email.
What the dashboard shows
Each monitor lists the certificate’s expiry date and days remaining, refreshed by the sweep. A certificate that renews (e.g. Let’s Encrypt auto-renewal) naturally resets its countdown — no action needed on your side.
Troubleshooting
- “Could not check” / no expiry shown — we couldn’t complete a TLS handshake: the host may be down, the port blocked, or the name wrong. Test it with the SSL Certificate Check tool.
- No alert email received — check spam for mail from
[email protected], and confirm the monitor’s thresholds aren’t all unchecked (that disables alerts for it). - Internal hosts — monitors probe from our infrastructure, so hosts behind a firewall/VPN aren’t reachable. The certificate must be visible from the public internet.