Endpoint check

SSL certificate expiry monitoring

DoubleCheck connects to your server, reads the certificate it presents and warns you 30 days before it expires, long before visitors see a browser warning.

The problem

Certificates expire on a fixed date, and automatic renewal fails more often than you would think: a changed DNS record, a firewall rule, a server that was moved. Nobody notices until the date has passed.

Certificates outside the main website are easy to forget: a mail server, a VPN portal, an API on another port.

Why it matters

An expired certificate puts a full-page warning in front of every visitor, and APIs and apps simply refuse to connect. It looks like an outage, and it is one.

Certificate lifetimes are getting shorter, which means more renewals and more chances for one to fail.

How to check it manually

Read the expiry date with openssl:

echo | openssl s_client -connect www.example.com:443 -servername www.example.com 2>/dev/null |
  openssl x509 -noout -enddate

Or click the padlock in your browser and open the certificate details. Then put a reminder in your calendar, for every certificate.

How DoubleCheck checks it

DoubleCheck opens a TLS connection to your host and port, just like a browser, and reads the certificate the server actually presents. That is the one that counts, not the one in your certificate store.

It checks the date and also whether the certificate is trusted and matches the host name, so a wrong or self-signed certificate is caught as well.

Measures
A TLS connection to your server (port 443 unless you set another), reading the expiry date of the certificate the server presents.
Runs
Every minute by default. You set the interval per check.
Status
  • OK when the certificate is valid for 30 days or more.
  • Warning when it expires within 30 days.
  • Error when the certificate has expired, is not trusted, does not match the host name, or the server cannot be reached.
FAQ

Frequently asked questions

When do I get a warning?

As soon as the certificate expires within 30 days. That leaves time to fix a renewal that failed.

Can I check a certificate on another port than 443?

Yes. You set the port per check, so mail servers, VPN portals and APIs on other ports can be checked too.

Does this also catch a wrong certificate?

Yes. A certificate that is not trusted or does not match the host name fails the connection and puts the check in error.

Why check every minute if certificates expire on a date?

You can set a longer interval. Checking often also catches a server that suddenly presents a different or wrong certificate, for example after a change on a load balancer.

Get started

Start monitoring with DoubleCheck

Alerts by email, SMS, Slack, Microsoft Teams or Discord. You pay per check run: cost management in the app shows what every check costs, and a longer interval lowers it.

Start monitoring