SSL, domain and uptime monitoring for agencies

Never let a client site lapse.

We check every client's certificates, domains, DNS and uptime, and tell you when an automatic renewal has quietly stopped, usually three weeks before the site breaks.

Start free5 domains, no card.

Any public hostname. We connect on port 443, read the certificate and check the chain, like a browser would.

client-site.example:443

22 DAYS
Expires
17 Oct 2026
Days left
22
Issuer
Let's Encrypt
Chain
Trusted
Renewal
Overdue
47-day ready
Ready (automated renewal)

Let's Encrypt certificates normally renew with about 30 days left. This one has 22, so auto-renewal has probably stopped. That's the email you want three weeks early.

Specimen. Run a check to see a real one.

01 — The rules changed

Certificates are getting shorter. The reminder emails already stopped.

Browser makers and certificate authorities voted to cut certificate lifetimes from 398 days to 47. Let's Encrypt had already stopped sending expiry emails.

  1. 4 Jun 2025no emailLet's Encrypt stops sending expiry reminder emails. A stalled renewal now fails silently. source
  2. Before 15 Mar 2026398daysThe longest a publicly trusted TLS certificate may last. Most paid certificates were sold as "one year". source
  3. 15 Mar 2026200daysMaximum lifetime drops to 200 days (CA/Browser Forum Ballot SC-081v3). source
  4. 15 Mar 2027100daysMaximum lifetime drops to 100 days. Renewing by hand becomes a quarterly job per site. source
  5. 15 Mar 202947daysMaximum lifetime drops to 47 days. Roughly eight renewals a year for every host you look after. source

Sources: CA/Browser Forum Ballot SC-081v3 (April 2025), Let's Encrypt, “Expiration notification service has ended” . More in our guide to 47-day certificates.

02 — What we do differently

An expiry date is the last thing to go wrong, not the first.

Everyone can count down to an expiry date. The useful warning comes earlier, when the thing that renews the certificate stops working.

  1. 01

    Renewal-failure prediction

    Automated certificates renew with about a third of their life left. When one sails past that point, the automation has stopped. We flag it the same day, usually three weeks before the certificate expires. For Let's Encrypt we read the renewal window the CA itself publishes (ARI).

  2. 02

    Subdomain discovery

    We search Certificate Transparency logs for every client domain and show the hosts nobody listed: old staging sites, campaign pages, the webmail. One click adds them.

  3. 03

    47-day readiness

    Each client gets a score: how many of their certificates renew themselves, and which ones someone still renews by hand. That list is the work to do before March 2027.

  4. 04

    Domain risk, not just expiry

    Daily RDAP lookups for expiry, registrar, transfer lock and statuses such as redemption or pending delete, plus alerts when nameservers or MX records change.

  5. 05

    White-label for clients

    Group sites by client. Send monthly PDF reports with your logo and a short written summary, and give each client a status page on their own domain.

  6. 06

    Lives in your stack

    Alerts go where your team already looks: Slack, Teams, Discord, Telegram, email or a signed webhook. Data comes out through an iCal feed, a REST API, an MCP server and an embeddable widget.

  7. 07

    Flat pricing per agency

    One price for the whole agency, not per monitor. Agency is $29 a month for 250 domains and unlimited clients.

03 — Lives in your stack

Alerts go where your team already looks.

You shouldn't need another dashboard open all day. Pick the channels, pick the severity for each, and carry on.

WhereWhat you getHow
SlackAlerts in a channel, and a slash command to ask about a clientIncoming webhook + slash command
Microsoft TeamsAlerts as cards in a channelIncoming webhook / Workflows
DiscordAlerts in a channel, coloured by severityWebhook
TelegramAlerts to a chat or groupBot message
WebhooksEvery incident as signed JSONHMAC-SHA256 signature header
Zapier, Make, n8nTickets, sheets, SMS, anything they connect toVia the signed webhook
CalendarExpiry dates in Google Calendar, Outlook or Apple CalendariCal feed URL
REST APIMonitors, certificates, domains and incidents as JSONAPI keys, read and write
MCP serverAsk Claude or ChatGPT about your portfolioModel Context Protocol
WidgetCertificate status inside your own client portalScript tag or iframe
Status pagesA public page per client, on their domainHosted page + CNAME

04 — Pricing

Priced per agency, not per monitor.

Add a client's fifteen subdomains without doing sums first.

Compare plans
PlanPer monthDomainsClients
Free$051
Freelancer$95010
Agency$29250Unlimited
Agency Pro$791,000Unlimited

Pay yearly and get two months free.

05 — FAQ

Things agencies ask us

Isn't SSL monitoring something my uptime monitor already does?

Most uptime monitors warn you when a certificate is close to expiry. We also tell you when an automated certificate has missed its normal renewal, weeks earlier, and we watch domain registration, DNS changes and the hosts you forgot to add.

My certificates are from Let's Encrypt. Why would I need this?

Because automation fails quietly. A DNS change, a server move or a plugin update can stop renewals, and Let's Encrypt stopped sending expiry reminder emails on 4 June 2025. We notice the missed renewal within six hours.

What happens when certificates are limited to 47 days?

Under CA/Browser Forum Ballot SC-081v3 the maximum certificate lifetime falls to 200 days in March 2026, 100 days in March 2027 and 47 days in March 2029. Hand-renewed certificates become a constant chore; automated ones need watching because there is less slack when they fail.

How often do you check?

Certificates every 6 hours, domain registration daily (twice a day in the last 30 days), DNS hourly, and uptime every 15 minutes on the free plan down to every 1 minute on Agency Pro.

Is the free plan really free?

Yes. 5 domains, one client, email and chat alerts, no card and no time limit. Paid plans add more domains, clients, seats and white-label reports.

Can my clients see ExpiryOwl?

Only if you want them to. Reports, status pages and the widget carry your name and logo on the Agency plans. On the free plan they show a small powered-by line.

Start with five domains, free.

The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.