Sign in to watch a domain
Up to 3 domains free. Look through the tool below, then sign in to start watching a certificate.
Sign in🔒 SSL, Expiry & DNS Change Monitor
Watch your domains' TLS certificates and get emailed before they expire.
Watch a domain
Enter a bare hostname - no "https://", no path, e.g. example.com. Checked roughly once a day; you'll be emailed once a certificate is within 14 days of expiring.
Your watched domains
What the daily check actually does
A scheduled run once a day does three things. It opens a TCP connection to your
domain on port 443, completes the TLS handshake, and reads the NotAfter
date off the certificate it is handed. It asks a WHOIS server when the
registration of the domain itself expires. And it asks a DNS
resolver for your A, AAAA, MX and
NS records. No page is ever fetched from your site - no HTTP
request, nothing downloaded. The days left and the colour of the dot come
from the certificate date:
days left = ceil((NotAfter - now) / 1 day)
expired or <= 14 days red and one warning email
15 to 28 days amber an early heads-up, no email
29 days or more green
no successful check grey "Not checked yet"
A certificate valid until 30 September, seen on 9 September, shows 21 days left in amber. Seven days later it crosses into red and the email goes out.
The registration check
Separate from the certificate, and warned about earlier - 30 days rather than 14. The two failures are not equally bad: a certificate you let lapse breaks HTTPS until you renew it, while a registration you let lapse can be registered by somebody else, and then the domain is simply gone.
A domain WHOIS reports as unregistered is not treated as an error - the watch just never fires, which is its own useful signal if you are waiting for a name to become free.
The DNS check, and why it does not cry wolf
The same daily run records your A, AAAA, MX
and NS records and compares them with the previous reading. If they
changed, you get one email showing both the old and the new values. A changed
MX record means mail is going somewhere else; a changed NS
record means control of the domain itself has moved, which is the most serious thing
this page can tell you.
Three rules keep that email worth opening:
- A failed lookup is never reported as a change. If the resolver does not answer, the last known-good reading is kept and nothing is sent. "Your DNS changed" would be the most alarming thing we could say, and a timeout is not that.
- The first reading is silent. There is nothing to compare it against, so adding a domain never sets off an alert on day one.
- Addresses have to hold still.
MXandNSare reported the first time they differ.AandAAAAare only reported once the same new value has appeared twice in a row - because a domain behind a CDN such as CloudFront or Cloudflare is handed a rotating set of edge addresses, and those change on their own without anyone touching the zone.
Records are read, not stored in full: what is kept is a short digest
used for the comparison, plus the readable list so the email can show you what
changed. TXT records are deliberately not watched - they change constantly
with verification tokens nobody wants an email about.
Adding a domain and reading the row
- Bare hostnames only.
example.comorapi.example.com, neverhttps://example.com, a path, or an explicit port - every check is made on 443. - The email goes to the address on your account, copied onto the monitor when you add the domain.
- One email per certificate. The warning re-arms only when the observed expiry date changes, so a certificate you have not renewed does not nag you daily, and a renewed one is watched again from scratch.
- Three domains are free. While SimpleMoney is in beta there is no charge for the ones after that. A check gives up after 8 seconds.
Frequently asked questions
How much warning do I get before a certificate expires?
Fourteen days. The email is sent on the first daily run that sees the certificate inside that window, and an already-expired certificate counts as inside it.
Does this tell me when my domain registration expires?
Yes, since 28 September 2026. The same daily run looks the registration date up over WHOIS and warns you 30 days ahead - wider than the 14 days used for certificates, on purpose: renewing a certificate takes minutes and is often automatic, while a registration you let lapse can be registered by somebody else and may not be recoverable at any price.
Until that date this page read the TLS certificate only, and this answer said so. If you set up a watch before then, it now covers both dates without you doing anything.
Can I watch a server on a port other than 443?
No. A hostname with a port is rejected and every handshake is made on 443, so mail and database certificates on other ports are out of scope.