---
title: "How does Lemwatch track SSL certificate expiry? — Lemwatch…"
description: "Lemwatch reads the TLS certificate on every uptime check and starts alerting 30, 14, 7, and 1 day before expiry so you never ship an expired cert."
canonical: "https://lemwatch.com/help/ssl-expiry-tracking"
source: "https://lemwatch.com"
---

# How does Lemwatch track SSL certificate expiry?

> Lemwatch reads the TLS certificate on every uptime check and starts alerting 30, 14, 7, and 1 day before expiry so you never ship an expired cert.

## Quick answer

 During every HTTPS uptime probe we read the leaf certificate, extract the notAfter date, and schedule reminders at T-30, T-14, T-7, and T-1 day. Auto-renewed certs simply refresh the countdown.

## What we surface

- Days until expiry

- Issuer (Let's Encrypt, DigiCert, etc.)

- Chain validity

- Subject alternative names

- TLS version (1.2 vs 1.3)

## Where to find it in Lemwatch

 **Site → Security → SSL**.

## FAQ

### Do you support wildcard certs?

 Yes — SAN entries are tracked individually.

### What about self-signed certs?

 We surface them but do not send expiry alerts.

## Related

- DNS change monitoring

- Security headers


## Related

- [Help centre](https://lemwatch.com/help)
- [How does Lemwatch detect DNS record changes?](https://lemwatch.com/help/dns-change-monitoring)
- [Security Headers Explained](https://lemwatch.com/help/security-headers)
- [How does Lemwatch detect WordPress plugins and themes?](https://lemwatch.com/help/wordpress-fingerprinting)
- [What is the Money Page Monitor?](https://lemwatch.com/help/money-page-monitor)
- [Lemwatch pricing](https://lemwatch.com/pricing)
- [SSL Certificate Monitoring](https://lemwatch.com/help/ssl-monitoring)
- [SPF record check](https://lemwatch.com/help/spf-record-check)
