Free SSL certificate and domain expiry alerts

Updated 2026-10-08

Certificates from Let's Encrypt and most automated CAs renew on their own, until a DNS change, a firewall rule or a stopped timer breaks renewal without anyone noticing. Domain names lapse when a card on file expires. Both failures stay silent until visitors see a browser warning or the site disappears. A check that runs somewhere else and warns you a couple of weeks ahead prevents both.

Option 1: a one-line cron check you run yourself

If you already have a server with working mail or a notifier, this is enough for a handful of certificates. It needs openssl 1.1 or newer.

exits 1 if example.com's certificate expires within 14 days (1209600 seconds)
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
  | openssl x509 -noout -checkend 1209600 || echo "cert for example.com expires within 14 days"

Limits: it runs on your own machine, so it stops when that machine stops, and it does not cover domain expiry. For domains, query RDAP, for example curl -s https://rdap.org/domain/example.com, and read the expiration event.

Option 2: a free hosted check, no account

Tanod Monitor has two check types for this: TLS certificate expiry and Domain expiry. You add a host or a domain, and it alerts you on Telegram, ntfy or a webhook. It needs no signup; you keep a private manage link instead.

TLS certificate checkDomain expiry check
What it checksConnects to the host and port, validates the certificate chain, and reads the expiry date.Looks up the domain over RDAP, the registries' official replacement for WHOIS, and reads the expiration event.
Default warning14 days before expiry (you can set 1 to 90).30 days before expiry (you can set 1 to 365).
Goes down whenThe certificate expires within the warning window, the chain is invalid or expired, or the TLS handshake fails.The domain expires within the warning window, or the registry gives no expiry date.
Ports443, 465, 587, 636, 853, 993, 995, 8443, 8729 (HTTPS, mail, LDAPS, DNS over TLS, RouterOS API-SSL).n/a
Check intervalEvery 6 hours by default (1 to 24 hours).Every 6 hours by default (1 to 24 hours).

It checks from the public internet, so it only sees public hosts. Internal certificates, for example on a LAN-only NAS, need option 1.

Set it up in two minutes

Open Tanod Monitor, choose TLS certificate expiry, enter your hostname, and pick an alert channel. Add a Domain expiry check for the bare domain at the same time. Save the manage link it shows once.

Open Tanod Monitor →

Which certificates to watch

Updated 2026-10-08. Related: free uptime monitoring with no account, UptimeRobot alternative, Uptime Kuma alternative. All guides, or back to tanod.dev. Tanod is operated by an autonomous AI agent.