SSL, domain and uptime monitoring for agencies
Never let a client site lapse.
We check every client's certificates, domains, DNS and uptime, and tell you when an automatic renewal has quietly stopped, usually three weeks before the site breaks.
Any public hostname. We connect on port 443, read the certificate and check the chain, like a browser would.
client-site.example:443
22 DAYS- Expires
- 17 Oct 2026
- Days left
- 22
- Issuer
- Let's Encrypt
- Chain
- Trusted
- Renewal
- Overdue
- 47-day ready
- Ready (automated renewal)
Let's Encrypt certificates normally renew with about 30 days left. This one has 22, so auto-renewal has probably stopped. That's the email you want three weeks early.
Specimen. Run a check to see a real one.
01 — The rules changed
Certificates are getting shorter. The reminder emails already stopped.
Browser makers and certificate authorities voted to cut certificate lifetimes from 398 days to 47. Let's Encrypt had already stopped sending expiry emails.
- 4 Jun 2025no emailLet's Encrypt stops sending expiry reminder emails. A stalled renewal now fails silently. source
- Before 15 Mar 2026398daysThe longest a publicly trusted TLS certificate may last. Most paid certificates were sold as "one year". source
- 15 Mar 2026200daysMaximum lifetime drops to 200 days (CA/Browser Forum Ballot SC-081v3). source
- 15 Mar 2027100daysMaximum lifetime drops to 100 days. Renewing by hand becomes a quarterly job per site. source
- 15 Mar 202947daysMaximum lifetime drops to 47 days. Roughly eight renewals a year for every host you look after. source
Sources: CA/Browser Forum Ballot SC-081v3 (April 2025), Let's Encrypt, “Expiration notification service has ended” . More in our guide to 47-day certificates.
02 — What we do differently
An expiry date is the last thing to go wrong, not the first.
Everyone can count down to an expiry date. The useful warning comes earlier, when the thing that renews the certificate stops working.
- 01
Renewal-failure prediction
Automated certificates renew with about a third of their life left. When one sails past that point, the automation has stopped. We flag it the same day, usually three weeks before the certificate expires. For Let's Encrypt we read the renewal window the CA itself publishes (ARI).
- 02
Subdomain discovery
We search Certificate Transparency logs for every client domain and show the hosts nobody listed: old staging sites, campaign pages, the webmail. One click adds them.
- 03
47-day readiness
Each client gets a score: how many of their certificates renew themselves, and which ones someone still renews by hand. That list is the work to do before March 2027.
- 04
Domain risk, not just expiry
Daily RDAP lookups for expiry, registrar, transfer lock and statuses such as redemption or pending delete, plus alerts when nameservers or MX records change.
- 05
White-label for clients
Group sites by client. Send monthly PDF reports with your logo and a short written summary, and give each client a status page on their own domain.
- 06
Lives in your stack
Alerts go where your team already looks: Slack, Teams, Discord, Telegram, email or a signed webhook. Data comes out through an iCal feed, a REST API, an MCP server and an embeddable widget.
- 07
Flat pricing per agency
One price for the whole agency, not per monitor. Agency is $29 a month for 250 domains and unlimited clients.
03 — Lives in your stack
Alerts go where your team already looks.
You shouldn't need another dashboard open all day. Pick the channels, pick the severity for each, and carry on.
| Where | What you get | How |
|---|---|---|
| Slack | Alerts in a channel, and a slash command to ask about a client | Incoming webhook + slash command |
| Microsoft Teams | Alerts as cards in a channel | Incoming webhook / Workflows |
| Discord | Alerts in a channel, coloured by severity | Webhook |
| Telegram | Alerts to a chat or group | Bot message |
| Webhooks | Every incident as signed JSON | HMAC-SHA256 signature header |
| Zapier, Make, n8n | Tickets, sheets, SMS, anything they connect to | Via the signed webhook |
| Calendar | Expiry dates in Google Calendar, Outlook or Apple Calendar | iCal feed URL |
| REST API | Monitors, certificates, domains and incidents as JSON | API keys, read and write |
| MCP server | Ask Claude or ChatGPT about your portfolio | Model Context Protocol |
| Widget | Certificate status inside your own client portal | Script tag or iframe |
| Status pages | A public page per client, on their domain | Hosted page + CNAME |
04 — Pricing
Priced per agency, not per monitor.
Add a client's fifteen subdomains without doing sums first.
Compare plans| Plan | Per month | Domains | Clients |
|---|---|---|---|
| Free | $0 | 5 | 1 |
| Freelancer | $9 | 50 | 10 |
| Agency | $29 | 250 | Unlimited |
| Agency Pro | $79 | 1,000 | Unlimited |
Pay yearly and get two months free.
05 — FAQ
Things agencies ask us
Isn't SSL monitoring something my uptime monitor already does?
Most uptime monitors warn you when a certificate is close to expiry. We also tell you when an automated certificate has missed its normal renewal, weeks earlier, and we watch domain registration, DNS changes and the hosts you forgot to add.
My certificates are from Let's Encrypt. Why would I need this?
Because automation fails quietly. A DNS change, a server move or a plugin update can stop renewals, and Let's Encrypt stopped sending expiry reminder emails on 4 June 2025. We notice the missed renewal within six hours.
What happens when certificates are limited to 47 days?
Under CA/Browser Forum Ballot SC-081v3 the maximum certificate lifetime falls to 200 days in March 2026, 100 days in March 2027 and 47 days in March 2029. Hand-renewed certificates become a constant chore; automated ones need watching because there is less slack when they fail.
How often do you check?
Certificates every 6 hours, domain registration daily (twice a day in the last 30 days), DNS hourly, and uptime every 15 minutes on the free plan down to every 1 minute on Agency Pro.
Is the free plan really free?
Yes. 5 domains, one client, email and chat alerts, no card and no time limit. Paid plans add more domains, clients, seats and white-label reports.
Can my clients see ExpiryOwl?
Only if you want them to. Reports, status pages and the widget carry your name and logo on the Agency plans. On the free plan they show a small powered-by line.
Start with five domains, free.
The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.