SSL certificate
Is the certificate valid, trusted, and not about to expire?
Opens a TLS connection and inspects the certificate. It checks the certificate, not the page.
Use it when
Always, on anything served over HTTPS. An expired certificate takes a site down as completely as a crashed server, it does so on a schedule you could have known about months ahead, and it tends to happen at weekends.
What to enter
| Field | Notes |
|---|---|
| URL or host | A URL, or host / host:port. Port 443 if not given. |
| Expiry warning | How many days' notice, 1 to 365. Default 14. |
Fourteen days suits automated renewal — enough to notice a renewal that silently stopped working, not so much that the warning becomes background noise. If renewal is manual, give yourself 30.
Exactly when it's DOWN
- The TLS handshake fails.
- Verification fails: an untrusted or incomplete chain, or a hostname that does not match.
- The certificate has already expired.
- The certificate expires within the warning window.
That last one is the point of the monitor: it goes down before anything is actually broken, which is the only useful time to find out.
What it doesn't do
- It does not check the page, the status code or the content. Pair it with an HTTP or Keyword monitor.
- It checks the certificate the server presents for that hostname. If you serve several certificates from one address, monitor each hostname.
Example
Host example.com, warning 14 days. Quick add creates one of these for you alongside the HTTP monitor.
Alerts
Down (including "expiring soon") and recovered.
Last updated 4 October 2026
Still stuck?
If this did not answer your question, tell us and we will fix the page as well as answer you.