Skip to main content
by PingZen Team

How to Monitor SSL Certificate Expiry (and Get Alerted Before It Breaks)

An expired TLS certificate is one of the most avoidable outages there is. The site is up, the server is healthy, the application works — and yet every visitor hits a full-screen browser warning telling them the connection is not private. Conversion drops to zero in an instant, and you usually find out from an angry customer rather than from your own tooling.

The fix is boring and reliable: monitor the certificate’s expiry date and alert yourself with enough lead time to renew calmly.

Why uptime checks alone miss it

A plain HTTP or ping check answers one question: is the server responding? A server with an expired certificate answers “yes” — the TCP connection succeeds, the TLS handshake technically completes, and many naive checks report the site as up. Meanwhile real browsers refuse to load the page.

That gap is exactly why certificate expiry needs its own dedicated check, not a side effect of a generic uptime monitor.

What a good SSL check actually verifies

  • Days until expiry — the headline number you alert on.
  • Certificate chain validity — an incomplete or out-of-order chain fails on some clients even before expiry.
  • Hostname match — the certificate is actually issued for the domain you requested, not a stale default.
  • Issuer / CA — useful for catching an unexpected re-issue.

Setting it up in PingZen

PingZen has a dedicated SSL protocol that connects to your domain, reads the live certificate, and tracks the expiry date on every check.

  1. Create a new monitor and choose the SSL protocol.
  2. Enter your domain (for example example.com:443).
  3. Leave the two thresholds at their defaults, or adjust them: the monitor turns amber 14 days before expiry and starts alerting at 7 days.
  4. Attach an alert channel (Telegram, Slack, Discord, Email, or a webhook).

From then on you get a heads-up well before the certificate lapses, with a second reminder as the deadline approaches. If you already monitor the site over HTTPS, add the SSL monitor alongside it: the HTTPS monitor answers “is the site up right now”, the SSL monitor answers “will TLS still work next month”. The SSL certificate documentation covers the thresholds and which services this monitor can and cannot watch.

A sensible renewal lead time

Automated issuers like Let’s Encrypt renew a 90-day certificate when 30 days are left, and the renewal should be automatic. But automation fails quietly: a cron job stops, a hook breaks, a DNS challenge times out. That is why the default warning sits at 14 days rather than 30 — at 30 days the alert would fire during every healthy renewal, while 14 days left means the renewal has genuinely been failing for two weeks and you still have time to fix it.

Certificates are also getting shorter: Let’s Encrypt already issues 6-day certificates, and the maximum lifetime drops to 47 days by 2029. A fixed 7-day critical threshold would keep a 6-day certificate permanently in the red, so PingZen caps both thresholds by the certificate’s own lifetime — the warning never exceeds a third of it, the critical never a sixth. Keep the automation, and keep the monitor as your safety net.


Ready to stop finding out about expired certificates from your customers? Create a free SSL monitor — it takes about a minute, no card required. For the full list of what PingZen can watch, see the supported protocols.

Ready to monitor your site?

Start free

No credit card · about a minute to set up