Lemwatch reads the TLS certificate on every uptime check and starts alerting 30, 14, 7, and 1 day before expiry so you never ship an expired cert.
During every HTTPS uptime probe we read the leaf certificate, extract the notAfter date, and schedule reminders at T-30, T-14, T-7, and T-1 day. Auto-renewed certs simply refresh the countdown.
Site → Security → SSL.
Yes — SAN entries are tracked individually.
We surface them but do not send expiry alerts.