SSL certificate expiry monitoring

SSL certificate expiry monitoring with auto-fetch and team reminders

Lapsewise monitors SSL certificate expiry dates across your domains, auto-fetches the expiry date directly from the live certificate chain, and sends reminders at 60, 30, 7 and 0 days before each cert expires. No more manual date entry. No more browser security warnings discovered by users.

Free plan available. No credit card required.

Why a spreadsheet is not enough

An expired SSL certificate does not just break HTTPS. It triggers full-page browser security warnings, kills checkout flows, tanks organic traffic overnight and signals to visitors that the site is unsafe. The damage happens in minutes. Discovery usually comes from a user complaint.

DevOps teams often rely on a cron job that pings a domain, a monitoring service alert that gets noise-cancelled, or a spreadsheet with dates that nobody updates. When an engineer leaves or a domain migrates, the coverage disappears with them.

Lapsewise adds the business layer that pure monitoring tools skip: document storage for the cert file, cost tracking for paid certificates, team assignment so the right engineer gets the reminder, and a record per domain that lives beyond any one person.

Everything in one place

Auto-fetch expiry from the live certificate

Paste a domain name and Lapsewise reads the expiry date directly from the live TLS certificate via a handshake. No manual date entry needed. The date is always accurate because it comes from the cert itself.

Reminders at 60, 30, 7 and 0 days

Once the expiry date is set, Lapsewise schedules all four reminder touchpoints automatically. Reminders fire at 08:00 in each recipient's local timezone, with the domain name and days remaining in the subject line.

Multi-domain tracking

Track every domain your team manages in one place: production sites, staging environments, client sites, CDN endpoints. Sort the list by next expiry to see what needs attention first.

Document storage for certificate files

Attach the certificate file, CSR or renewal confirmation to each domain record. Useful for internally-issued certificates, wildcard certs that need manual renewal and compliance audits that require proof.

Team assignment

Assign each domain to the DevOps engineer, IT admin or web developer who owns its renewal. They get the reminder; the noise does not go to everyone.

Cost tracking for paid certificates

Record the annual cost of commercial or wildcard certificates alongside the domain record. See your upcoming cert renewal spend by month and avoid surprise invoices.

Powered by the Lapsewise renewal engine

The same dependable engine that tracks certifications, contracts and grants.

One runway of every date

See what is coming up across every record, sorted by urgency, on a single calm dashboard.

Reminders before it lapses

Email, SMS and Slack reminders fire in each person's own timezone, days before the deadline.

Documents attached

Drop the PDF onto the record. The file lives in private per-workspace storage, ready when you need to prove it.

AI reads the dates

Upload a document and AI extracts the dates, type and parties. You confirm, it fills the record.

Who it is for

DevOps and platform engineering teamsIT administratorsSaaS companies managing multiple environmentsEcommerce businesses where checkout SSL is criticalDigital agencies managing client websitesWeb developers with client hosting responsibilities

Frequently asked questions

What is SSL certificate expiry monitoring?

SSL certificate expiry monitoring is the practice of tracking when TLS/SSL certificates are due to expire and alerting the responsible team before they do. An expired certificate causes browsers to show a security warning page that blocks users from reaching the site. Lapsewise monitors expiry dates across all your domains, auto-fetches dates from the live certificate chain, and sends reminders before any cert lapses.

How often do SSL certificates expire?

Let's Encrypt certificates expire every 90 days, which is why auto-renewal via Certbot or ACME is standard for those. Commercial, extended validation and wildcard certificates from paid CAs typically expire after one year. The 90-day cycle is short enough that a failed auto-renewal goes unnoticed for weeks before causing an outage, which is why external monitoring matters even when auto-renewal is configured.

What happens when an SSL certificate expires?

Every major browser shows a full-screen security warning that prevents users from reaching the site unless they manually click through a series of override prompts. Search engines may de-index pages. Checkout and payment flows break immediately. API clients receiving certificate errors stop connecting. The impact is immediate and broad, which is why catching the expiry 30 or 60 days in advance matters.

How does the auto-fetch feature work?

When you add a domain record in Lapsewise, the system performs a TLS handshake with the domain's server and reads the Not After field from the certificate response. This gives the exact expiry date without manual entry. The lookup works for any domain reachable over HTTPS, including subdomains and wildcard certificate holders.

How does Lapsewise differ from UptimeRobot or Zabbix for SSL monitoring?

Monitoring tools like UptimeRobot and Zabbix are excellent for detecting when a site goes down or a cert is already expired. Lapsewise complements them by operating earlier in the lifecycle: it tracks the upcoming expiry date, sends multi-stage reminders weeks in advance, stores the cert document, tracks the renewal cost and assigns ownership to a named team member. It is the business-context layer, not a real-time availability monitor.

How much does it cost?

Lapsewise has a free plan for up to 5 domain and SSL records with email reminders included. Paid plans are flat per workspace: Starter at $19 per month for unlimited records and CSV import; Pro at $49 per month adds SMS, Slack notifications and AI document parsing. No per-user seat fees.

Track more than ssl certificate expiry monitoring

Never let it lapse

Lapsewise monitors SSL certificate expiry dates across your domains, auto-fetches the expiry date directly from the live certificate chain, and sends reminders at 60, 30, 7 and 0 days before each cert expires. No more manual date entry. No more browser security warnings discovered by users.

Start tracking free