How to monitor SSL certificate expiry
An expired SSL certificate replaces your website with a full-page browser warning. It is one of the most avoidable causes of downtime — and still one of the most common.
Why certificates expire unnoticed
Certificates have a fixed lifetime. Free certificates from Let's Encrypt last 90 days and are meant to renew automatically; commercial certificates traditionally ran for a year or more. Automation fixes the routine case, but renewal depends on DNS, server settings and billing staying intact. When any of those change, renewal can fail with no visible symptom until the old certificate runs out. Industry rules are also shortening maximum certificate lifetimes — the CA/Browser Forum has approved a schedule that steps the maximum down to 47 days by 2029 — which makes reliable renewal, and watching it, more important, not less.
Check your expiry date manually
- Open your site in Chrome and click the padlock (or the site-information icon) next to the address.
- Choose Connection is secure, then Certificate is valid.
- Read the Valid to date.
On the command line: openssl s_client -connect yourdomain.com:443 -servername yourdomain.com </dev/null 2>/dev/null | openssl x509 -noout -enddate
Automate the watching
A manual check only helps if you remember to do it. A monitor reads the certificate on a schedule and warns you with plenty of time. A good setup has three layers:
- A countdown you can see — days remaining for every certificate in one place.
- An early alert — at 30 days if you can, so renewal problems are a calm task, not a fire.
- A failure check — your uptime monitor should fail loudly if the certificate is invalid or expired, so you also catch mismatched or incomplete chains.
OwlHound checks the certificate your site presents about every hour, emails you daily once 14 days or fewer remain, and shows the countdown in every weekly report. See how SSL and domain monitoring works.
Don't forget subdomains and the domain itself
Each hostname you serve over HTTPS has its own certificate: www, app, shop, status. Monitor each one. And remember that the domain registration expires separately — a lapsed domain breaks the site, the certificate renewal and your email together.
Frequently asked questions
How long does an SSL certificate last?
Let's Encrypt certificates last 90 days and renew automatically. Commercial certificates were traditionally valid for a year or more, but the maximum lifetime is being reduced in stages, so check the exact dates your provider issues.
What happens when an SSL certificate expires?
Browsers show a full-page security warning and most visitors leave. Anything calling your site over HTTPS, such as an app or an API client, will usually fail outright.
How early should I renew?
Renew at least two weeks before expiry, which leaves time to fix any validation problems. Most automated systems renew with 30 days left or earlier.
Start watching your site in minutes
7-day trial. No installs and no passwords — we only check public pages.