IP Cow logo IP Cow

Privacy-first IP, DNS & email tools · 20+ years of serving your IP

SSL-expiry monitoring

Monitor TLS certificates and get emailed before they expire — setup, thresholds, alternate recipients.

SSL monitoring watches your hosts’ TLS certificates and emails you before they expire — the outage you only notice when customers do. Available on paid plans (see quotas); extra monitors come in +50 blocks as an add-on.

Add a monitor

On Dashboard → SSL monitors, enter the host and click Add monitor:

  • example.com — checks port 443
  • example.com:8443 — a non-standard HTTPS port works too

Anything with a TLS certificate a public probe can reach is fair game: websites, APIs, mail hosts on their TLS ports. Monitored hosts (and alternate emails) are encrypted at rest.

Warning thresholds

Pick when to be warned: 30, 14, 7, 3 and 1 days before expiry (all on by default). We check each certificate at least daily, and you get one email per threshold crossing — not a daily nag. Thresholds are editable per monitor, inline, at any time.

Alternate recipients

Each monitor can CC up to 5 extra addresses (comma-separated) — your ops list, an on-call alias, a client. They receive the same threshold alerts as your account email.

What the dashboard shows

Each monitor lists the certificate’s expiry date and days remaining, refreshed by the sweep. A certificate that renews (e.g. Let’s Encrypt auto-renewal) naturally resets its countdown — no action needed on your side.

Troubleshooting

  • “Could not check” / no expiry shown — we couldn’t complete a TLS handshake: the host may be down, the port blocked, or the name wrong. Test it with the SSL Certificate Check tool.
  • No alert email received — check spam for mail from [email protected], and confirm the monitor’s thresholds aren’t all unchecked (that disables alerts for it).
  • Internal hosts — monitors probe from our infrastructure, so hosts behind a firewall/VPN aren’t reachable. The certificate must be visible from the public internet.