How do I monitor SSL certificate expiry?
Part of SSL certificate monitoring — the full answer, the facts and the alternatives in one place.
Quick answer
How do I monitor SSL certificate expiry?
Use an SSL monitor that connects over TLS, reads the certificate's notAfter field, and emails you 30, 14, 7 and 1 day before expiry. Lemwatch does this automatically for every site you add.
- Let's Encrypt certificates renew every 90 days; missed renewals cause instant browser trust errors.
- Monitor the whole chain, not just the leaf — intermediate CA expiry breaks Firefox and iOS Safari first.
- Check the SNI hostname you actually serve, not just the apex domain.
- Alert 30 days out so you have a full renewal window even if your CI is broken.
Step-by-step
- 1Add the hostname
Enter the exact hostname you serve (including www or subdomain) so SNI matches production.
- 2Enable SSL monitoring
Turn on the SSL check — it runs a TLS handshake and reads notAfter daily.
- 3Set alert thresholds
Alert at 30, 14, 7 and 1 day out. The first alert is your work-week buffer.
- 4Verify the full chain
Confirm the monitor also validates intermediates so iOS Safari does not break silently.