SSL certificate monitoring built into every HTTPS check

Every Uptime Tracker HTTPS monitor validates the TLS certificate on each check. An expired, untrusted or wrong-hostname certificate fails the check and sends an alert, and the certificate expiry date is visible on the monitor. This is included on all plans, including Free.

Free plan · no credit card · or compare plans

[ 001 ]

Validated on every check

The certificate is verified each time the monitor runs, at your normal check interval.

[ 002 ]

Broken certificates alert you

Expired, untrusted or hostname-mismatched certificates fail the check and open an incident.

[ 003 ]

Expiry date visible

Each HTTPS monitor shows when its certificate expires, so renewals are easy to review.

[ 004 ]

TLS timing recorded

The TLS handshake time is part of every response-time breakdown.

[ 005 ]

No extra monitor needed

Certificate checks come with your existing HTTPS monitors, at no extra cost.

What SSL certificate monitoring catches

Uptime Tracker treats a bad TLS certificate as an outage, because to a visitor it is one: browsers show a full-page warning and most people leave. On every HTTPS check the certificate is validated, and the check fails if any of these is true:

  • The certificate has expired. The most common cause is an automated renewal that silently stopped working.
  • The certificate is untrusted. For example a self-signed certificate, a missing intermediate certificate, or a chain that does not lead to a trusted root.
  • The hostname does not match. The certificate was issued for www.example.com but the monitor requests example.com, or a load balancer is serving the wrong certificate for a domain.

When the check fails, the normal failure confirmation applies: the monitor is re-checked, and two consecutive failures open an incident and send alerts to your channels. Because the certificate is checked at the monitor's interval, a broken certificate is caught within minutes on Free and within about a minute on Starter or Team.

Missing intermediates and hostname mismatches are worth calling out. They often appear right after a server migration, CDN change or new load balancer, and they may not show up in your own browser if it has cached the intermediate certificate. An independent check catches them for everyone.

Certificate expiry dates and renewal planning

The certificate expiry date is shown on every HTTPS monitor, so you can see at a glance which certificates are close to renewal. If a certificate does expire, the next check fails and you are alerted immediately.

Uptime Tracker does not yet send separate advance-warning emails before a certificate expires. Here is what that means in practice and how to cover it:

  • Automated renewal (for example Let's Encrypt with certbot or a managed CDN): certificates renew about a month before expiry. If renewal breaks, you see the expiry date approaching on the monitor, and an expired certificate triggers an alert. Pair this with a heartbeat on the renewal job to catch failures sooner (see below).
  • Manually purchased certificates: note the expiry date shown on the monitor in your calendar or ticket system, and review the monitor list as part of a monthly routine.

A useful trick for automated renewals is to monitor the renewal job itself. Add a heartbeat monitor to an hourly task that runs your renewal check and pings only on success. If the renewal tooling breaks, you hear about it from the heartbeat weeks before the certificate would expire.

Exporting your monitors as CSV also gives you a quick inventory of every domain you watch, which helps when auditing certificates across many sites.

Pair certificate checks with domain-expiry monitoring

A valid certificate does not help if the domain registration itself lapses, so the most complete protection pairs SSL checks with domain-expiry monitoring. An expired domain takes down your website, email and every certificate issued for it at the same time, and recovering it can be slow or impossible once it enters the registry's deletion cycle.

The two checks cover different renewal processes:

SSL certificate checkDomain-expiry check
What it watchesThe TLS certificate served by your siteThe domain registration at the registry
Data sourceThe live HTTPS connectionRDAP registration data
Advance warningExpiry date shown; alert when invalid or expiredConfigurable warning 1 to 90 days ahead (default 30)
PlanAll plans, including FreeStarter and Team

Domain-expiry monitors do send advance warnings, so on Starter and Team you get a heads-up weeks before a registration lapses. Together with certificate validation on every HTTPS check, that covers the two renewals most likely to take a working site offline overnight.

Set up SSL certificate monitoring

There is no separate SSL monitor to configure: any HTTPS monitor validates the certificate automatically.

  1. Sign in and add an HTTP(S) monitor using the https:// address of your site.
  2. Add a monitor for each hostname that has its own certificate, for example example.com, www.example.com, app.example.com and api.example.com. Each one may be served by a different certificate or server.
  3. Choose alert channels. Certificate failures arrive through the same channels as downtime alerts.
  4. Open the monitor to confirm the certificate expiry date is shown.
  5. On Starter or Team, add a domain-expiry monitor for each registered domain.

Monitoring each hostname separately matters. A common failure is a certificate that covers www but not the bare domain, or a subdomain served from a different platform whose certificate is renewed on a different schedule. One monitor per public hostname catches those cases.

If you manage many client sites, import them in bulk with CSV. See uptime monitoring for agencies for a setup that groups sites by client.

What's included on each plan

SSL certificate validation is part of every HTTPS check on every plan; what changes between plans is how quickly a broken certificate is detected and how alerts are routed.

FreeStarterTeam
Certificate validation on HTTPS checksYesYesYes
Expiry date shown on monitorYesYesYes
Check interval5 minutes60 seconds30 seconds
Domain-expiry monitors with advance warningsNoYesYes
SMS and routing rulesNoYesYes

The check interval is the main reason to upgrade for certificate monitoring. On Free, a certificate that breaks during a deploy is caught within about 5 minutes plus a confirmation re-check; on Starter and Team it is caught within a minute or two. For a busy store or SaaS login page, that difference is real.

Starter also adds domain-expiry monitors with advance warnings, which complement certificate checks, and SMS alerts with routing rules so certificate failures on critical hostnames reach a phone. See the pricing page for all limits.

FAQ

Frequently asked questions

Does Uptime Tracker monitor SSL certificates for free?

Yes. Every HTTPS monitor on every plan, including Free, validates the TLS certificate on each check. Expired, untrusted or hostname-mismatched certificates fail the check and send an alert.

Will Uptime Tracker warn me before my SSL certificate expires?

Not with a separate advance-warning email yet. The expiry date is visible on every HTTPS monitor, and an expired or invalid certificate triggers an alert immediately. To catch broken renewals earlier, add a heartbeat monitor to your renewal job.

Can it detect a missing intermediate certificate?

Yes. A certificate chain that does not lead to a trusted root is treated as untrusted, so the check fails and you are alerted. This often catches problems after a server or CDN change that your own browser may hide.

Do I need a separate monitor for each subdomain?

Yes, add one HTTPS monitor per public hostname. Different hostnames can be served by different certificates or servers, and one monitor per hostname catches mismatches and certificates that are renewed on different schedules.

What is the difference between SSL monitoring and domain-expiry monitoring?

SSL monitoring checks the certificate your server presents over HTTPS. Domain-expiry monitoring checks the domain registration through RDAP and warns 1 to 90 days ahead. SSL checks are on every plan; domain-expiry monitors require Starter or Team.

Uptime Tracker

Start monitoring in under five minutes

Start on the free plan — commercial use allowed. No credit card, no password, just your email address.

  • Free forever plan
  • No credit card
  • Cancel anytime