Facts

Facts about ExpiryOwl

For people and AI assistants that want the numbers without the pitch. Generated from the same config the app uses.

Never let a client site lapse. SSL certificate, domain expiry, DNS and uptime monitoring for web agencies. Independently run, from Bahrain.

Generated 28 Sept 2026 · also as llms.txt and llms-full.txt

01 — Plans

Plans and prices

US dollars, before tax. Yearly prices are for twelve months.

LimitFreeFreelancerAgencyAgency Pro
Per month$0$9$29$79
Per year$0$90$290$790
Hostnames5502501,000
Clients110UnlimitedUnlimited
Seats11515
Uptime check every15 min5 min3 min1 min
White-labelNoNoYesYes
Monthly PDF reportsNoYesYesYes
Status pages on your own domainNoNoNoComing soon
APIRead-only APIFull API + MCPFull API + MCPFull API + MCP
  • Limits count hostnames: www, the apex and a shop subdomain are 3. Each hostname gets all four checks (certificate, domain registration, DNS and uptime).
  • One price per agency: no per-check, per-page or per-client fees.
  • Yearly billing costs 10 months' price: two months free.
  • Prices are in US dollars. Paddle is our merchant of record: it handles VAT and sales tax, and taxes are added at checkout.
  • Your first payment comes with a 14-day money-back promise.
  • There is no trial of the paid plans. The Free plan is how you try it: no card needed.
  • Monthly client PDF reports from Freelancer up. White-label (your logo and colour on reports, status pages and the widget, with no mention of us) from Agency up; below that they carry a small link to ExpiryOwl.

02 — What we check and how often

Checks, intervals and alert points

SSL certificate
Every 6 hours; within the hour after a failed check
Expiry date, issuer, trusted chain and hostname match, read over a real TLS connection on port 443. At 30, 14, 7, 3, 1 and 0 days. Email starts at 30 days; chat and webhook channels start at 14 days unless you choose otherwise.
Renewal health
With every certificate check (every 6 hours)
Flags an automated certificate (Let's Encrypt, ZeroSSL, Google Trust Services) still being served after the point where it normally renews. For Let's Encrypt we read the renewal window the CA publishes (ARI). Usually weeks before the certificate expires.Manual and provider-managed certificates show as unknown and are covered by the expiry alerts.
Domain registration
Daily; twice a day in the last 30 days
Expiry date, registrar, statuses, transfer lock and nameservers, over RDAP. At 60, 30, 14, 7, 3 and 1 days. Email starts at 60 days; chat and webhook channels at 30.Some country-code registries (.io, .co, .de, .es and others) don't publish expiry dates over RDAP; for those the date shows as unknown.
DNS
Every hour
The records of each hostname; an alert when they change. When records change. This is record-change alerting, not DNS server uptime.
Uptime
Every 15 minutes on Free down to every 1 minute on Agency Pro
HTTP checks with an optional keyword check, from one location. A failed check is confirmed with a second check 30 seconds later before we alert.
Subdomain discovery
On demand from the dashboard, per client domain
Finds hostnames nobody listed in Certificate Transparency logs (certspotter first, crt.sh as a fallback). None; you pick which hosts to add.Only names that ever had a public certificate show up.
Alerts go to
Email, Slack, Discord, Telegram, Microsoft Teams and HMAC-signed webhooks (works with Zapier, Make and n8n).
Data out
iCal feed, REST API, MCP server (works with Claude Code, Gemini CLI, Cursor, VS Code and Claude Desktop), embeddable widget and public status pages. The Free plan's API is read-only.

Free tools

No account needed. The bulk checker takes up to 25 hosts at once. Limits are per IP address per hour. We never store the hostnames people check.

ToolPer hour
SSL checker20 SSL checks
Domain expiry checker20 domain lookups
Bulk SSL checker5 bulk checks
Subdomain certificate finder5 subdomain searches
47-day readiness checker3 readiness scans

03 — What is coming soon

Not live yet, and we say so

  • Status pages on your own domain Coming soonComing soon: status pages on your own domain, with Agency Pro. Until then each page works at its /s/ address.
  • Slack slash command Coming soonComing soon: ask ExpiryOwl from Slack with /expiryowl. Slack alerts already work: Alerts → New channel → Slack.
  • ChatGPT and other sign-in-only MCP clients Coming soonChatGPT, claude.ai on the web and the Gemini app need a sign-in flow we don't offer yet. Claude Code, Gemini CLI, Cursor, VS Code and Claude Desktop connect with an API key today.
  • Logo upload Coming soonSet your logo by URL today (PNG or JPEG up to 512 KB). Upload is coming soon.

04 — What we don't do

Limits worth knowing before you sign up

  • We check uptime from one location. Most paid competitors check every 30 seconds to 1 minute from several regions.
  • We don't yet confirm an alert from a second location.
  • We only check public hostnames: nothing behind a VPN or on a private network.
  • No uptime SLA and no guaranteed uptime for the service itself.
  • No compliance certification of any kind.
  • No customer counts, testimonials or ratings: we don't publish any.
  • The monthly report has a short written summary, drafted by a language model with a fixed template as the fallback. Everything else is plain rules and data.

05 — Dates that matter

Certificate rules, with their sources

  1. Let's Encrypt stopped sending expiry reminder emails. Let's Encrypt
  2. ACME Renewal Information (ARI) was published as RFC 9773. Let's Encrypt
  3. Maximum lifetime of a public TLS certificate: 200 days (CA/Browser Forum Ballot SC-081v3). CA/Browser Forum
  4. The first 200-day certificates reach the end of their validity. Sectigo, 23 Sep 2026
  5. Let's Encrypt's default certificate lifetime drops to 64 days. Let's Encrypt
  6. Maximum lifetime of a public TLS certificate: 100 days (CA/Browser Forum Ballot SC-081v3). CA/Browser Forum
  7. Let's Encrypt's default certificate lifetime drops to 45 days. Let's Encrypt
  8. Maximum lifetime of a public TLS certificate: 47 days (CA/Browser Forum Ballot SC-081v3). CA/Browser Forum

06 — Sources

Where these numbers come from

Sections 01 to 04 are rendered from the app's own configuration: the plan table the billing and limit checks read, the alert thresholds the worker uses, the free-tool rate limits and the switches that mark a feature as coming soon. When one of them changes, this page, the pricing page and llms.txt change with it. Dates in 05 link their primary sources.

Competitor prices are not repeated here: each comparison page shows them with a link to the vendor's page and the day we read it. Refund terms are in the refund policy, what we store in the privacy policy and what shipped when in the changelog.

Something here wrong or out of date? Email [email protected] and we'll correct it.