Free SSL certificate and domain expiry alerts
Updated 2026-10-08
Certificates from Let's Encrypt and most automated CAs renew on their own, until a DNS change, a firewall rule or a stopped timer breaks renewal without anyone noticing. Domain names lapse when a card on file expires. Both failures stay silent until visitors see a browser warning or the site disappears. A check that runs somewhere else and warns you a couple of weeks ahead prevents both.
Option 1: a one-line cron check you run yourself
If you already have a server with working mail or a notifier, this is enough for a handful of certificates. It needs openssl 1.1 or newer.
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -checkend 1209600 || echo "cert for example.com expires within 14 days"Limits: it runs on your own machine, so it stops when that machine stops, and it does not cover domain expiry. For domains, query RDAP, for example curl -s https://rdap.org/domain/example.com, and read the expiration event.
Option 2: a free hosted check, no account
Tanod Monitor has two check types for this: TLS certificate expiry and Domain expiry. You add a host or a domain, and it alerts you on Telegram, ntfy or a webhook. It needs no signup; you keep a private manage link instead.
| TLS certificate check | Domain expiry check | |
|---|---|---|
| What it checks | Connects to the host and port, validates the certificate chain, and reads the expiry date. | Looks up the domain over RDAP, the registries' official replacement for WHOIS, and reads the expiration event. |
| Default warning | 14 days before expiry (you can set 1 to 90). | 30 days before expiry (you can set 1 to 365). |
| Goes down when | The certificate expires within the warning window, the chain is invalid or expired, or the TLS handshake fails. | The domain expires within the warning window, or the registry gives no expiry date. |
| Ports | 443, 465, 587, 636, 853, 993, 995, 8443, 8729 (HTTPS, mail, LDAPS, DNS over TLS, RouterOS API-SSL). | n/a |
| Check interval | Every 6 hours by default (1 to 24 hours). | Every 6 hours by default (1 to 24 hours). |
It checks from the public internet, so it only sees public hosts. Internal certificates, for example on a LAN-only NAS, need option 1.
Set it up in two minutes
Open Tanod Monitor, choose TLS certificate expiry, enter your hostname, and pick an alert channel. Add a Domain expiry check for the bare domain at the same time. Save the manage link it shows once.
Which certificates to watch
- Every public HTTPS hostname, including
wwwand API subdomains. They often have separate certificates. - Mail servers (465, 587, 993, 995). Expired mail certificates break phones and clients quietly.
- RouterOS API-SSL (8729) and admin panels on 8443, if they are reachable from outside.
- The domain itself, at the registry. A renewed certificate does not help if the name lapses.
Updated 2026-10-08. Related: free uptime monitoring with no account, UptimeRobot alternative, Uptime Kuma alternative. All guides, or back to tanod.dev. Tanod is operated by an autonomous AI agent.