Pereiti prie turinio

SSL monitoring that warns you before expiry.

One missed renewal and every visitor sees a security warning instead of your site. Uptimia warns you up to 90 days before each certificate expires — and within minutes when one breaks.

30-day free trial · up to 50 SSL certificates No credit card GDPR-ready
Warn up to
90days
Break to alert
10min
Alert channels
12
Server changes
0

One certificate's last 60 days

A live certificate, re-read every 10 minutes. The warning window opens at 60 days, the severity flips at 45, and the renewal closes it.

issued billing.caldmont.com — certificate healthyRe-read every 10 minutes: issuer, dates, protocol, handshake time browser warning: none
60 days Your warning window opensThe heads-up you configured: TROUBLE at 60 days — renew calmly browser warning: none
45 days Still unrenewed? It escalates itselfInside 45 days the same monitor turns CRITICAL — an emergency, not a note browser warning: none
renewed Back to green — by itselfThe next read sees the new valid-to date; incident closes, countdown resets browser warning: never
0browser warnings
Nobody saw a warning.renewed
The countdown never reached zero. Visitors typed their card numbers into a padlocked page the whole time — and the renewal happened on your calendar, not at 2 a.m. after it broke.
60-day heads-up — yours to set45-day critical — automaticcleared itself on renewalchain · protocol · hostname — same watch
And without the countdown? Certificates don't expire gradually — the second the "valid to" timestamp passes, every browser slams the door at once. "Your connection is not private" is how your visitors find out for you. day zero

SSL monitoring beyond the expiry date

A certificate can break long before it expires — Uptimia's HTTPS monitoring checks the whole handshake: chain, protocol, hostname.

Expiring & expired certsCaught inside your warning window
Broken certificate chainsMissing intermediates · bad issuers
Weak & deprecated TLSOld protocol versions negotiated
Renewals & rotationsVerified when the new cert lands
10 min · every check a real handshake, not a date lookup
Any HTTPS domain you runWeb, API, mail — same watch
Failed TLS handshakesHTTPS unreachable or refused
Hostname & domain mismatchThe cert for the wrong name
Alerts fire on five conditions: expiry inside your window, chain errors, a weak or deprecated protocol, a hostname or domain mismatch, or a failed handshake. 5 conditions

Expiry, chain and protocol

Certificate expiration alerts, on your schedule

Warned days ahead, never after

Set how much warning you want, per domain. Once a check lands inside that window, the alert fires — a lapsed certificate never surprises you.

  • You choose how much notice you get — set it per certificate, in days
  • Checked against the live valid-to date every run — not a cached lookup
  • Clears itself the moment a renewed certificate is detected
Alerts on 12 channels, one contact list
📆Live valid-toAug 02, 2026 · read every check12 days
🔔Your thresholdper monitor · dial 7, 30, 60…30 days
12 < 30inside your
window
Renew soon09:12
shop.caldmont.com entered your 30-day window — you hear about it 12 days ahead, never after.
Let's Encrypt · R11TLS 1.3
Renewed the certificate? The next check reads the new valid-to and the alert clears itself — nothing to resolve by hand. self-clearing
Right urgency, less noise

Two severities, one monitor

A generous warning window fires a low-key TROUBLE alert; inside 45 days of expiry — or already lapsed — it escalates to CRITICAL. A single blip never pages you.

  • 45-day severity boundary — trouble further out, critical inside 45 days or expired
  • A blip never wakes anyone — a problem has to hold across consecutive checks first
  • Recovery notice closes the loop the moment the certificate is renewed
Page the next person until someone acknowledges
Expiry approaching60 d left
billing.caldmont.com — the same monitor changes its tone as the date gets closer. No siren until it's earned.
SlackEmailSMS+ Teams, WhatsApp…
60
Trouble — a calm heads-up
60 days out · your warning window opens
trouble
45
Critical — now it's loud
inside 45 days, or already expired · same monitor
critical
Recovered — new certificate
valid to Oct 05, 2026 · recovery notice sent
cleared
One odd check never pages you — a problem has to repeat before anyone hears about it. no blip pages
More than a date

Chain, protocol and hostname

An unexpired certificate can still break the padlock. Every check validates the chain, negotiated protocol and hostname — and opens an incident the moment any is wrong.

  • Chain validity — a missing intermediate or untrusted issuer is flagged
  • Weak & deprecated protocols — know when a server negotiates something it shouldn't
  • Hostname & domain match — the cert actually covers the address it's served on
Free tool: which TLS versions your server offers
HANDSHAKEapi.caldmont.com
last check · 118 ms · every check runs all three
chainleaf → R11 → ISRG Root X1complete
protonegotiated TLS 1.3strong
hostSAN covers api.caldmont.commatch
expiryvalid to Aug 21, 202634 days
Chain check
intermediates present + trusted
missing R11? → incident
Protocol check
negotiated TLS 1.3 
TLS 1.0 offered? → incident
Hostname check
cert covers the address served
www-only cert? → incident
A green padlock can still be broken — chain, protocol and hostname are validated on every check, not once a week. every check
Real numbers, your cadence

Real handshake times, at your pace

Every check records the TLS handshake time the probe measured on the live connection. You pick the cadence per certificate, from every 10 minutes up to once a day.

  • Handshake time in milliseconds — what the probe recorded on the live connection
  • Check interval you choose — from every 10 minutes up to once every 24 hours
  • Update one setting via API without resetting the rest of the monitor
The checkpoints our checks come from
Cadence you choose
every 10 min → once a day
per certificate · as often as every 10 min
One-setting API update
{"check_interval": 600}
the rest stays untouched
handshake time — caldmont.comprobe-measured · last 7 d
MonThuSun
last check
118 ms
cadence
10 min
checks / week
1,008
Watch it drift — a handshake that slows week on week shows up long before anything breaks. real ms

Point it at a domain.Hear about expiry weeks out.

Every certificate, every chain check, every alert channel — free for 30 days, and none of it is a paid add-on.

Start your free 30-day trial
30 days free no credit card cancel anytime

How SSL monitoring works

Live in under a minute — nothing to install, Uptimia reads the certificate your server presents.

Step 120 seconds

Add your HTTPS domain

Paste the domain and pick your warning window — sensible defaults cover the rest.

Domain
https://caldmont.com
certificate read · valid to Aug 21 · TLS 1.3
Check interval
Every 10 minutes
Warn me before expiry
30 days
Step 220 seconds

Choose who gets alerted

Pick people and channels, and how many failing checks confirm a real problem.

Send alerts via
EmailSlackSMS+ Teams, Telegram, PagerDuty…
Confirm after
3 consecutive failed checks
CancelStart monitoring →
Step 3automatic

Uptimia watches the handshake

Every 10 minutes it re-reads the live certificate and alerts your team days before expiry — or the instant something's wrong.

#ops-alerts
Uptimia 09:12
⚠ Critical — caldmont.com cert expires in 30 days
renew nowLet's Encrypt R11valid to Aug 21
Also sent to EmailSMS

Also included

Full REST API

Create, edit and manage certificate monitors from CI or scripts — partial updates change one setting and leave the rest untouched.

PATCH /api/v2/ssl/6 200 · sets expire_alert_days:30 · keeps everything else

The whole handshake, validated

Not just the expiry date — the whole handshake is validated.

chain · protocol · hostname

Incident history that holds

A chain problem that opened before this month still shows in the window you're viewing.

open · started Jun 3 · still listed

Check interval you control

From every 10 minutes up to once a day, per certificate.

every 10 min ↑ up to 24 h

Fewer false pages

Require up to three failing checks before an incident confirms.

confirm after 3 failed checks

Every monitor type in one account

Your SSL monitors sit beside uptime, speed, DNS and heartbeat monitors — same contacts, groups and roles.

caldmont.comSSL www.caldmont.comUPTIME db-backup · nightlyHEARTBEAT

Where your alerts land

An expiring certificate reaches the same people, on the same channels, as a site that went down.

On-call & escalation
Direct

12 channels, one contact list — set it once, every monitor type uses it.

Browse the full integrations directory
09:12 · certificate expiring — caldmont.com · 30 days left
#ops-alertsSlack
⚠ Renew now — caldmont.com
expires in 30 daysLet's Encrypt R11Acknowledge ↩
+371 ··· 4082SMS
Uptimia: SSL cert for caldmont.com expires in 30 days (Aug 21). Time to renew.
InboxEmail
⚠ Certificate expiring — caldmont.com · 30 days left
Valid to Aug 21, 2026. Issued by Let's Encrypt R11 · acknowledge with one click…
ProductionPagerDuty
CRITICALCert expiring — caldmont.com
assigned to on-call · via Uptimia integration

What is SSL monitoring?

SSL monitoring — also called SSL certificate monitoring or TLS certificate monitoring — is an automated service that periodically opens a real TLS connection to your HTTPS site, reads the certificate it presents, and alerts you before that certificate expires — or the moment its chain, protocol or hostname is wrong. It runs from outside your servers, so problems are fixed days ahead of a browser warning.

On every check

How does SSL monitoring work?

Uptimia
every 10 min
TLS handshake
Your certificate
issuer · dates · TLS 1.3

Each check reads the live certificate — issuer, validity dates, negotiated protocol and real handshake time.

When something's wrong

When does an SSL monitor alert you?

Certificate
30 days to expiry
inside your window
Uptimia
opens the alert

expiry inside your warning window, or a bad chain / protocol / hostname → alert

The urgency ladder

When does an expiry alert become critical?

You set the warning window; a fixed 45-day boundary then tells routine from urgent, so a heads-up weeks out never reads like an emergency.

Free tool: check any certificate once
Days to expirySeverityWhat Uptimia does
Outside your windowNothing yet — the certificate is healthy
Inside window, > 45 daysTroubleA calm heads-up: renew soon
45 days or lessCriticalAn urgent alert: act now
Already expiredCriticalAn urgent alert: renew immediately

SSL monitoring FAQ

01What is SSL monitoring?+
An automated service that watches your SSL/TLS certificate from the outside and alerts you before it expires — or when its chain, protocol or hostname is wrong. Uptimia's SSL monitoring tool opens a real TLS handshake every 10 minutes and reads the live certificate.
02How does Uptimia check my SSL certificate?+
It completes a TLS handshake with your domain and parses the certificate presented — issuer, validity dates, negotiated protocol and real handshake time. No agent to install: checks run from Uptimia's network.
03How far ahead will I be warned before a certificate expires?+
As far ahead as you choose — the "warn me before expiry" threshold defaults to 7 days and can be set anywhere from 1 to 90 days. Inside that window the alert fires; inside 45 days (or once expired) it escalates to critical.
04How often does Uptimia check the certificate?+
As often as every 10 minutes, up to once every 24 hours — per certificate. Ten minutes is the minimum: a certificate's configuration doesn't change second to second. (For sub-minute checks of whether a site is up, that's uptime monitoring.)
05Does SSL monitoring catch more than an expiry date?+
Yes. Every check validates the chain (missing intermediate, untrusted issuer), the negotiated TLS protocol (weak or deprecated), and the hostname — that the certificate covers the address it's served on. Any failure opens an incident.
06Does it check certificate revocation, mixed content or force HTTPS-only?+
No. SSL monitoring watches certificate expiry, chain validity, protocol strength and hostname match — it does not perform OCSP/CRL revocation checks, scan for mixed content, or police HTTP-to-HTTPS redirects.
07Will Uptimia renew my certificate automatically?+
No. Uptimia detects and alerts — it doesn't issue, install or auto-renew certificates, and isn't tied to Let's Encrypt, ACME or any CA. Once you renew, the next check reads the new expiry date and clears the alert on its own.
08Can I monitor SSL certificate expiration for all my domains?+
Yes — add as many SSL monitors as your plan allows, each with its own interval and warning window. The 30-day trial includes room for up to 50 certificates.
09Can I just check a certificate once instead of monitoring it?+
Yes — the free SSL Certificate Checker gives a one-shot report (cert details, chain, TLS version, grade) with a shareable link. For continuous warning, turn the domain into an SSL monitor.
10Is SSL monitoring included in the free plan?+
SSL monitoring starts with the paid plans — every paid plan includes it alongside uptime, transaction, DNS and server monitoring, never as a paid add-on, and plans differ only in how many certificates you can watch. The 30-day free trial includes it in full (up to 50 certificates, no credit card); after the trial, SSL monitors pause until you're on a plan that includes them, while free-plan uptime monitoring keeps running.

Start monitoring your certificates today.

Point Uptimia at a domain — be warned days before a certificate turns a visitor away.

30-day free trial Up to 50 SSL certificates No credit card EU-hosted, GDPR-ready
SSL monitoring is available on the free trial and every paid plan.