SSL Certificate Monitoring
Monitors your SSL certificates' validity and warns you before they expire.
- Daily
- automatic checks
- 60/30/7
- days advance alerts
- Wildcard+SAN
- coverage
- notification
An expired certificate breaks visitor trust and loses customers.
Your websites, panels and subdomains have SSL/TLS certificates that are not forever — they must be renewed every year or two. Most of the time the expiry date is forgotten and visitors see "This site is not secure" when they try to access your site. Trust is lost, conversion rate drops. If you have dozens of subdomains, manual tracking is impossible. Automatic monitoring is essential.
- Which of your certificates are about to expire? How many days are left?
- Do I have expired or invalid certificates? They can fail too fast to catch.
- Are my wildcard and SAN certificates also monitored? Hidden subdomains may be left exposed.
What it does.
Daily automatic checks
All your domains and subdomains are scanned daily for certificate status; results are mirrored to the panel.
60, 30 and 7 days advance alerts
Email and panel notifications come 60, 30 and 7 days before expiry so you can renew in time.
Certificate chain verification
Root, intermediate and end-entity certificates are checked for full validity and any revocations.
Wildcard and SAN coverage
Wildcard and Subject Alt Name records covering up to 100 domains in a single certificate are automatically discovered.
Provider and type
CA (Let's Encrypt, Google Trust Services, Sectigo) is logged, as well as certificate type (DV, OV, EV) and algorithm.
Valid / invalid / expired status
Each certificate shows a clear status: active, invalid (chain/revocation error) or expired. Days remaining and exact expiry date are displayed.
Compliance reporting
All certificate management checks and history are retained for ISO 27001 audits, GDPR compliance and cyber insurance claims.
From setup to report.
- 01
Add domains
Enter your domains to monitor on the panel; subdomains will be auto-discovered.
- 02
Automatic scanning
Each day at specified times, ThreatChaser scans all your domains for certificates and verifies provider, type and chain.
- 03
Alert settings
Define the email address to receive alerts 60, 30, 7 days before expiry and on expiration.
- 04
Monitor on panel
All certificate status is visible in one table; valid, invalid and expired are color-coded.
- 05
Renewal and reporting
Renew expired certificates; scan results and history become reports for audits and compliance requests.
The specifics.
- Check frequency
- Daily automatic scanning
- Alert timing
- 60 days, 30 days, 7 days and day-of alerts
- Subdomain coverage
- Wildcard and SAN (Subject Alt Name) scope: up to 100+ domains in one certificate
- Certificate checks
- Validity status, chain and intermediate, revocation queries, provider and type
- Target type
- Fully qualified domain name (FQDN) — not IP address, domain names only
- Notification
- Email (60/30/7 days and expiry) + in-panel status code and alerts
- Data retention
- All scan results and history retained for compliance reporting
Frequently asked questions.
If my Let's Encrypt certificate auto-renews, do I need alerts?
Yes. Let's Encrypt certificates are valid for 90 days and usually auto-renew at 60 days. But if renewal fails (DNS error, access issue), the certificate can expire. ThreatChaser verifies renewal success through daily scans and alerts if renewal failed.
I have dozens of subdomains; how many are not covered by a single certificate?
ThreatChaser checks wildcard and SAN records in each scan. Subdomains not in SAN entries and outside wildcard scope need separate certificates. Scan results show these gaps.
What if my certificate is revoked?
The certificate status on the panel shows "Invalid". The reason for revocation (key compromise, misuse, etc.) appears in the email alert. You must urgently deploy a replacement certificate.
Other CyCastle services.
SSL Certificate Monitoring starts today.
Create a free account and run your first scan within minutes.