Skip to content

SSL certificate monitoring

Catch an expiring certificate before your client sees a security warning

Hosting auto-renewals fail silently — wrong email address, expired payment method, account mismatch. Most agencies rely on calendar reminders or manual checks. Sitewatch monitors every certificate continuously, alerts 30 days before expiry, and validates the full chain — not just whether the cert is technically valid.

  • 30-day early warning before SSL expiry, escalating to critical at 14 days
  • Checks the whole chain of trust, not just whether the certificate is valid
  • Automatic on every check — no API keys, no setup, just add a site

Free scan

Check your SSL certificate — free

Scan any URL in 20 seconds. Sitewatch checks your SSL certificate, chain, and TLS configuration — plus broken assets, security headers, and expiry — and flags anything at risk.

02How we compare

Most tools check the certificate. We check the trust.

The certificate is valid

Other tools:
Checked
Sitewatch:
Checked

You hear about it 30 days early

Other tools:
Usually only near or after expiry
Sitewatch:
Warned at 30 days, urgent at 14

The full chain of trust is verified

Other tools:
Most check the certificate only
Sitewatch:
Catches breaks that only fail on some devices

Outdated security protocols are flagged

Other tools:
Not checked
Sitewatch:
Reported before an audit finds them

Weak encryption settings are flagged

Other tools:
Not checked
Sitewatch:
Reported with what to change

Domain expiry is covered too

Other tools:
Rarely included
Sitewatch:
Bundled automatically

The alert tells you how to fix it

Other tools:
Alert only
Sitewatch:
A fix checklist per problem type

03Why it matters

Certificates fail silently. Your clients notice first.

The auto-renewal quietly failed

SSL_EXPIRED

Renewal depends on the right email reaching the right inbox and a working card on file. Agencies routinely find a client certificate lapsed because the reminder went to somebody who left two years ago.

UptimeNothing, until the site stops loading.
SitewatchWarns 30 days out regardless of whose inbox the reminder went to.

It works for you, not for your client

SSL_CHAIN_ERROR

The chain of trust connecting your certificate to a recognised authority is incomplete. Your browser fills in the gap and looks fine; your client's phone shows a full-page security warning.

UptimeThe certificate is valid — nothing flagged.
SitewatchChecks the whole chain, not just the certificate itself.

The server still offers outdated security

SSL_OLD_PROTOCOL

Old protocols that modern browsers refuse are still switched on, which fails security audits and can block visitors on stricter networks.

UptimeNot checked at all.
SitewatchFlags outdated protocols before an audit or a browser does.

The encryption is weaker than it looks

SSL_WEAK_CIPHER

The padlock shows, but the connection is negotiated with encryption that is considered broken. Security scanners and compliance reviews both flag it.

UptimeNot checked at all.
SitewatchReports any weak encryption setting still enabled.

04What we check

Every part of the padlock.

A working padlock depends on more than one thing being right. Select any part to see how it fails — and how Sitewatch catches it.

Expiry date

renewal

How it fails — The certificate lapses and every browser replaces your site with a full-page security warning.

How Sitewatch detects it — Warns 30 days before expiry, escalates at 14, and raises it as urgent on the day.

Chain of trust

intermediates

How it fails — The link between your certificate and a recognised authority is incomplete, so the site fails on some devices and works on others.

How Sitewatch detects it — Follows the whole chain on every check, rather than trusting what your own browser happens to accept.

Protocol

tls version

How it fails — The server still offers outdated protocols that modern browsers refuse and security audits fail you for.

How Sitewatch detects it — Reports any outdated protocol still enabled, with the setting to change.

Encryption strength

ciphers

How it fails — The padlock appears, but the connection is secured with encryption that is considered broken.

How Sitewatch detects it — Checks which encryption settings the server will accept and flags the unsafe ones.

Domain registration

ownership

How it fails — The domain itself lapses, which takes the site offline entirely — certificate or no certificate.

How Sitewatch detects it — Tracks registration expiry alongside the certificate and warns 30 days early.

05What we check

Expiry is just the start — we check the whole chain of trust

Certificate expiry

  • A certificate due to expire within 30 days, escalating as the date closes in
  • A certificate that has already expired, raised as urgent immediately

Certificate chain

  • A broken chain of trust, which makes the site fail on some devices while working on yours

TLS configuration

  • Outdated security protocols (TLS 1.0 and 1.1) that modern browsers now reject
  • Weak encryption settings that security scanners and audits flag as unsafe

06How it works

What happens on every check.

No separate scan to run, no keys to configure. Certificate checks are built into the same visit that verifies the rest of your page.

Start free
  1. 1

    Sitewatch opens your site

    On its normal schedule — there is no separate certificate scan to remember to run.

  2. 2

    Reads the certificate

    Who issued it, when it expires, how it chains back to a trusted authority, and how the connection is secured.

  3. 3

    Runs five checks in one pass

    Expiry window, chain integrity, protocol support and encryption strength are all evaluated together.

  4. 4

    Finds a problem

    An approaching expiry, a broken chain, an outdated protocol — anything that would show a visitor a security warning.

  5. 5

    Alerts you with a fix list

    Each incident arrives with how urgent it is, what it means in plain English, and a checklist of exactly what to change.

07What you get

Outcomes, not a feature list.

Never take a certificate phone call again.

Expiry is entirely predictable, which is what makes getting caught by it so painful to explain. Sitewatch watches every client certificate continuously and tells you a month out — long before anyone is looking at a security warning.

$ sitewatch ssl clientsite.com
certificate valid · issued by trusted authority
chain complete
protocol modern only
expires in 22 days
✕ renewal window open · 22 days to act

30 days

Early warning before a certificate expires.

5 checks

Expiry, chain, protocol, encryption and domain — every time.

Every check

No separate scan to run — it is always on.

Start monitoring SSL before the next expiry surprises you

Free plan. 1 site. SSL monitoring included. No credit card.

08FAQ

SSL monitoring questions