C
// MONITOR SSL CERTIFICATES

Monitor SSL certificates

Add your domains and CertFleet keeps watch — probing the live certificate your server actually serves on a schedule and alerting you well before expiry. Pair with DNS monitoring and domain expiry monitoring for complete domain health coverage.

Live TLS probe, not CA cache Alerts at 30 / 14 / 7 / 1 days Free for 10 certificates No credit card required
CertFleet SSL certificate fleet showing valid, expiring and expired certificates with issuer, TLS version, chain status and days remaining

SSL certificate fleet — every monitored domain with its issuer, TLS version, chain validity and exact days to expiry. VALID · EXPIRING · EXPIRED badges update on every probe.

An SSL certificate expiry causes a browser warning that blocks every visitor to your site. The browser does not distinguish between "certificate expired yesterday" and "server is down" — in both cases, users see a full-screen security error and leave. Monitoring SSL certificates means knowing about expiry 30 days in advance, not finding out when a user reports a broken padlock. The only way to be certain is to watch every domain continuously, not to rely on calendar reminders or manual checks.

The most common SSL failure is not a missed renewal — it is a renewal that succeeded but was never deployed. Let's Encrypt runs, a new certificate is written to disk, but the web server process is never reloaded. From the CA's perspective the renewal succeeded. From your users' perspective, the old certificate will expire on its original date. To catch this, monitoring must perform a real TLS handshake on port 443 and read the certificate your server actually presents — not the one in the CA's database. Tools that only check issuance records miss this failure entirely.

CertFleet's probe reads the full X.509 certificate from the live TLS handshake: the notAfter expiry date, the issuer and full CA chain, the Subject Alternative Names (which hostnames the cert actually covers), the TLS version negotiated, and the signature algorithm. A wildcard cert covering *.example.com may not cover the apex example.com — the SAN list confirms this. A chain that includes an expired intermediate causes browser warnings even if the leaf cert is valid — chain validation confirms the full trust path.

Certificate Transparency monitoring adds a security layer. Every publicly trusted CA must submit issued certificates to CT logs within 24 hours of issuance. CertFleet watches CT for your domains: when a new certificate appears — whether from your own automation or unexpectedly — an alert fires immediately. This closes two gaps: you see a successful renewal the moment the CA logs it (before it reaches port 443), and you see any unauthorized certificate issued for your domain within minutes, giving you time to request revocation before an attacker can exploit it.

Fleet coverage means monitoring every hostname, not just the main domain. The API subdomain, the admin panel, the staging environment someone provisioned six months ago and forgot about, the internal tool behind a load balancer — these are where the unexpected expiries happen. Each domain renews on its own schedule, with its own CA and its own deployment pipeline. CertFleet tracks each one independently, with its own expiry timeline and alert configuration. Adding a domain takes under a minute; monitoring starts immediately.

The free tier monitors 10 SSL certificates with no time limit — email and Slack alerts included. The Starter plan at $15/mo scales to 25 certificates with signed webhooks and full REST API access. Growth at $35/mo covers 100 domains with team RBAC, private certificate support, and CT new-issuance alerts. No infrastructure to maintain: CertFleet runs on Cloudflare Workers with an external TLS probe — no agent to install, no cron job to maintain.

CertFleet alert settings showing staged SSL certificate expiry notifications via email, Slack and webhook at 30, 14, 7 and 1 day thresholds

Per-certificate alert configuration — independent thresholds and channels for each domain. HMAC-signed webhooks deliver certificate serial, expiry date, days remaining, and issuer to any receiver.

Free — $0

10 SSL certs · email + Slack · 30/14/7/1d alerts · CT monitoring.

Starter — $15/mo

25 certs · signed webhooks · REST API · SMS · 1-min uptime checks.

Growth — $35/mo · popular

100 certs · team RBAC · private certs · CT new-issuance alerts · 3 users.

▸ START MONITORING

CertFleet probes the live certificate, watches Certificate Transparency, and alerts you 30/14/7/1 days before expiry. Free for 10 certificates, no card.

Built in France · Architecture & RGPD · All plans