StatusKit / ssl & domain expiry
// ssl + domain expiry monitoring

Never let a client's cert expire again.

An expired SSL certificate throws a full-page security warning. An expired domain takes the whole site — and the email — offline. Both fail silently, right up until the deadline. StatusKit watches every client's cert and domain and warns you at 30, 14, 7 and 1 days — long before anyone else notices.

0 agents
No install. Read from the live TLS handshake + RDAP, like a browser does.
30/14/7/1
Tiered alerts, each sent once when crossed — never spammed, never surprised.
One fleet view
Every client's cert & domain, sorted by days left. One screen, whole book of business.

01Expiry is the outage you cause yourself

Downtime usually arrives from the outside — a bad deploy, a DDoS, a provider hiccup. Certificate and domain expiry are different: you own the renewal, the date is known months ahead, and the failure is total when it lands. A lapsed cert turns every visitor's browser into a red warning screen. A lapsed domain deletes the site and the client's email in one stroke. For an agency, that's not a glitch — it's the client watching you miss a date you were paid to keep. StatusKit exists so that date never sneaks up.

02Four warnings, escalating — not one alarm

A single "it expires today" alert is useless; renewals take time. StatusKit escalates across four tiers so the warning matches the urgency — an early, calm heads-up, then sharper reminders as the deadline closes in. Each tier fires once when it's crossed, for both SSL certificates and domain registration:

30days
Heads-up

First notice — plenty of runway to renew calmly.

14days
On watch

Two weeks out. Put the renewal on someone's desk.

7days
Warning

One week. This is the escalation you can't ignore.

1days
Final call

24 hours. Renew now or the site breaks tomorrow.

Every alert names the site, says whether it's the certificate or the domain, and gives the exact days remaining — by email and by webhook, so it lands in Slack, Teams or PagerDuty next to the rest of your on-call.

03The whole book of business on one screen

Managing one site, a calendar reminder is enough. Managing forty client sites, calendar reminders are how things slip. StatusKit's Expiring-soon view collapses every certificate and domain you monitor into a single list sorted by days remaining, so a ten-second glance each Monday tells you exactly what to renew this week — across every client, in one place.

// spreadsheets & calendar pings

Dates you have to remember

  • A renewal date living in someone's head, or a stale spreadsheet
  • Certs and domains tracked in different places, if at all
  • You find out it lapsed when the client emails, furious
  • Onboarding a client means hunting down every expiry by hand
// statuskit expiring-soon view

Dates that watch themselves

  • Every cert & domain across every client, sorted by days left
  • One list — SSL and domain expiry side by side, always current
  • You hear about it at 30 days, not from an angry client at zero
  • New client = add the site once; the fleet view does the rest

04Nothing to install, nothing to access

You don't need a login to your client's server or registrar. StatusKit reads the certificate straight off the live TLS handshake and the domain's expiry straight from the public RDAP registry record — the same sources a browser and a registrar use. Add a hostname, and it's monitored. That means you can watch a prospect's sites before you've even onboarded them, and hand a client a branded status page without touching their infrastructure. Prefer to manage it in Git? The whole fleet can live in a version-controlled monitors.json.

05FAQ

How do I monitor SSL certificate expiry across many domains at once?

Add each site once and StatusKit watches its certificate on a schedule from the edge. The Expiring-soon fleet view then shows every cert and domain across all your clients sorted by days remaining, so one screen tells you what to renew this week. There's no per-server agent and no manual date-keeping — the whole fleet is one list.

How early does StatusKit warn me before a certificate expires?

At four tiers: 30, 14, 7 and 1 day before expiry. You get an early heads-up with room to renew calmly, then escalating reminders as the deadline closes in — each sent once when the threshold is crossed, so you're never spammed and never surprised. Domain registration expiry is watched on the same 30/14/7/1 ladder.

What's the difference between SSL expiry and domain expiry monitoring?

An SSL certificate expiring throws a full-page browser security warning — the padlock breaks and visitors are told the site is unsafe. A domain expiring is worse: the name stops resolving entirely and email dies with it. Both are silent until the deadline, both are catastrophic, and StatusKit watches both — cert via a live TLS probe, domain via RDAP registry data.

Can I monitor a client's SSL and domain without access to their server?

Yes. StatusKit reads the certificate straight off the live TLS handshake and the domain's expiry straight from the public RDAP registry record — exactly what a browser and a registrar see. You need nothing installed on their infrastructure and no credentials. If you can reach the site, you can monitor its cert and domain.

How does StatusKit alert me — email, webhook, Slack?

Email and webhook, the moment a threshold is crossed. Point the webhook at Slack, Microsoft Teams, PagerDuty or your own endpoint and expiry warnings land in the channel your team already watches. Every alert names the site, whether it's the cert or the domain, and the exact days remaining.

How much does SSL and domain monitoring cost?

Start free — the SSL & domain checker reads any site's certificate and domain expiry right now, no signup. Create an account to put a client fleet under continuous 30/14/7/1 monitoring with alerting and a branded status page. Pricing is flat per fleet, not per-seat — see the console.

// the date will never sneak up again

See what's expiring right now — free.

Paste any hostname into the free checker and read its live certificate and domain expiry in seconds. When you're ready, put a whole client fleet under 30/14/7/1 monitoring with alerts and a status page.