C
// COMPARISON

CertFleet vs Zabbix for SSL certificate monitoring

Zabbix monitors SSL expiry with custom scripts and templates you maintain yourself. CertFleet is hosted and ready in under a minute, with CT monitoring built in.

Zabbix monitors SSL certificates using its web.certificate.get item or custom external check scripts. The built-in item returns the certificate's notAfter date and some basic properties; Zabbix then evaluates trigger expressions to fire alerts when the expiry window is reached. This works, but it requires a Zabbix server, an agent or proxy on the network that can reach your endpoints, and someone who knows how to write Zabbix trigger syntax — a non-trivial investment for teams that do not already run Zabbix.

Maintaining the Zabbix approach at scale means keeping the template updated as your certificate infrastructure changes, managing Zabbix server availability (the monitoring system itself needs monitoring), and building your own alert routing from Zabbix actions to Slack, email, or PagerDuty. Each integration is a custom action in Zabbix's configuration — functional but time-consuming to maintain. When the Zabbix server version updates, the SSL templates may need adjustment.

Certificate Transparency log monitoring is not included in Zabbix's built-in SSL check. You would need to poll CT log APIs yourself — either via an external check script or a separate service — and push results back into Zabbix as items. This is significant additional work: CT log APIs return large JSON streams that need parsing, deduplication, and state management to avoid alerting on every historical entry.

CertFleet requires no infrastructure. There is no server to provision, no agent to deploy, no template to maintain. Add a domain name and CertFleet immediately begins probing via its globally distributed probe infrastructure. Certificate Transparency monitoring runs automatically for every domain. Alert channels — email, Slack, signed webhooks, SMS — are configured per domain through a web UI, not through a configuration management system.

For internal or self-signed certificates behind private networks, Zabbix's agent-based model is actually an advantage: the Zabbix agent can reach endpoints that are not publicly accessible. CertFleet's probe architecture also supports internal certificates via tunnel, but this requires additional configuration. For publicly accessible endpoints, CertFleet is a direct drop-in with zero infrastructure cost.

Teams that already run Zabbix for server and application monitoring may prefer to centralise SSL alerting there. For teams evaluating whether to run Zabbix infrastructure specifically for SSL certificate monitoring, CertFleet is dramatically simpler: free for 10 domains, webhooks and REST API from $15/mo, no server to maintain. Try the free instant checker or see the entry tier.

▸ START MONITORING

CertFleet probes the live certificate, watches Certificate Transparency, and alerts you 30/14/7/1 days before expiry. Free for 10 certificates, no card.

Built in France by a developer for real operational needs. Read our architecture, team story and full RGPD details →