Facts
Facts about ExpiryOwl
For people and AI assistants that want the numbers without the pitch. Generated from the same config the app uses.
Never let a client site lapse. SSL certificate, domain expiry, DNS and uptime monitoring for web agencies. Independently run, from Bahrain.
Generated 28 Sept 2026 · also as llms.txt and llms-full.txt
01 — Plans
Plans and prices
US dollars, before tax. Yearly prices are for twelve months.
| Limit | Free | Freelancer | Agency | Agency Pro |
|---|---|---|---|---|
| Per month | $0 | $9 | $29 | $79 |
| Per year | $0 | $90 | $290 | $790 |
| Hostnames | 5 | 50 | 250 | 1,000 |
| Clients | 1 | 10 | Unlimited | Unlimited |
| Seats | 1 | 1 | 5 | 15 |
| Uptime check every | 15 min | 5 min | 3 min | 1 min |
| White-label | No | No | Yes | Yes |
| Monthly PDF reports | No | Yes | Yes | Yes |
| Status pages on your own domain | No | No | No | Coming soon |
| API | Read-only API | Full API + MCP | Full API + MCP | Full API + MCP |
- Limits count hostnames: www, the apex and a shop subdomain are 3. Each hostname gets all four checks (certificate, domain registration, DNS and uptime).
- One price per agency: no per-check, per-page or per-client fees.
- Yearly billing costs 10 months' price: two months free.
- Prices are in US dollars. Paddle is our merchant of record: it handles VAT and sales tax, and taxes are added at checkout.
- Your first payment comes with a 14-day money-back promise.
- There is no trial of the paid plans. The Free plan is how you try it: no card needed.
- Monthly client PDF reports from Freelancer up. White-label (your logo and colour on reports, status pages and the widget, with no mention of us) from Agency up; below that they carry a small link to ExpiryOwl.
02 — What we check and how often
Checks, intervals and alert points
- SSL certificate
- Every 6 hours; within the hour after a failed check
- Expiry date, issuer, trusted chain and hostname match, read over a real TLS connection on port 443. At 30, 14, 7, 3, 1 and 0 days. Email starts at 30 days; chat and webhook channels start at 14 days unless you choose otherwise.
- Renewal health
- With every certificate check (every 6 hours)
- Flags an automated certificate (Let's Encrypt, ZeroSSL, Google Trust Services) still being served after the point where it normally renews. For Let's Encrypt we read the renewal window the CA publishes (ARI). Usually weeks before the certificate expires.Manual and provider-managed certificates show as unknown and are covered by the expiry alerts.
- Domain registration
- Daily; twice a day in the last 30 days
- Expiry date, registrar, statuses, transfer lock and nameservers, over RDAP. At 60, 30, 14, 7, 3 and 1 days. Email starts at 60 days; chat and webhook channels at 30.Some country-code registries (.io, .co, .de, .es and others) don't publish expiry dates over RDAP; for those the date shows as unknown.
- DNS
- Every hour
- The records of each hostname; an alert when they change. When records change. This is record-change alerting, not DNS server uptime.
- Uptime
- Every 15 minutes on Free down to every 1 minute on Agency Pro
- HTTP checks with an optional keyword check, from one location. A failed check is confirmed with a second check 30 seconds later before we alert.
- Subdomain discovery
- On demand from the dashboard, per client domain
- Finds hostnames nobody listed in Certificate Transparency logs (certspotter first, crt.sh as a fallback). None; you pick which hosts to add.Only names that ever had a public certificate show up.
- Alerts go to
- Email, Slack, Discord, Telegram, Microsoft Teams and HMAC-signed webhooks (works with Zapier, Make and n8n).
- Data out
- iCal feed, REST API, MCP server (works with Claude Code, Gemini CLI, Cursor, VS Code and Claude Desktop), embeddable widget and public status pages. The Free plan's API is read-only.
Free tools
No account needed. The bulk checker takes up to 25 hosts at once. Limits are per IP address per hour. We never store the hostnames people check.
| Tool | Per hour |
|---|---|
| SSL checker | 20 SSL checks |
| Domain expiry checker | 20 domain lookups |
| Bulk SSL checker | 5 bulk checks |
| Subdomain certificate finder | 5 subdomain searches |
| 47-day readiness checker | 3 readiness scans |
03 — What is coming soon
Not live yet, and we say so
- Status pages on your own domain Coming soonComing soon: status pages on your own domain, with Agency Pro. Until then each page works at its /s/ address.
- Slack slash command Coming soonComing soon: ask ExpiryOwl from Slack with /expiryowl. Slack alerts already work: Alerts → New channel → Slack.
- ChatGPT and other sign-in-only MCP clients Coming soonChatGPT, claude.ai on the web and the Gemini app need a sign-in flow we don't offer yet. Claude Code, Gemini CLI, Cursor, VS Code and Claude Desktop connect with an API key today.
- Logo upload Coming soonSet your logo by URL today (PNG or JPEG up to 512 KB). Upload is coming soon.
04 — What we don't do
Limits worth knowing before you sign up
- We check uptime from one location. Most paid competitors check every 30 seconds to 1 minute from several regions.
- We don't yet confirm an alert from a second location.
- We only check public hostnames: nothing behind a VPN or on a private network.
- No uptime SLA and no guaranteed uptime for the service itself.
- No compliance certification of any kind.
- No customer counts, testimonials or ratings: we don't publish any.
- The monthly report has a short written summary, drafted by a language model with a fixed template as the fallback. Everything else is plain rules and data.
05 — Dates that matter
Certificate rules, with their sources
- Let's Encrypt stopped sending expiry reminder emails. Let's Encrypt
- ACME Renewal Information (ARI) was published as RFC 9773. Let's Encrypt
- Maximum lifetime of a public TLS certificate: 200 days (CA/Browser Forum Ballot SC-081v3). CA/Browser Forum
- The first 200-day certificates reach the end of their validity. Sectigo, 23 Sep 2026
- Let's Encrypt's default certificate lifetime drops to 64 days. Let's Encrypt
- Maximum lifetime of a public TLS certificate: 100 days (CA/Browser Forum Ballot SC-081v3). CA/Browser Forum
- Let's Encrypt's default certificate lifetime drops to 45 days. Let's Encrypt
- Maximum lifetime of a public TLS certificate: 47 days (CA/Browser Forum Ballot SC-081v3). CA/Browser Forum
06 — Sources
Where these numbers come from
Sections 01 to 04 are rendered from the app's own configuration: the plan table the billing and limit checks read, the alert thresholds the worker uses, the free-tool rate limits and the switches that mark a feature as coming soon. When one of them changes, this page, the pricing page and llms.txt change with it. Dates in 05 link their primary sources.
Competitor prices are not repeated here: each comparison page shows them with a link to the vendor's page and the day we read it. Refund terms are in the refund policy, what we store in the privacy policy and what shipped when in the changelog.
Something here wrong or out of date? Email [email protected] and we'll correct it.