For managed service providers
Certificate and domain expiry monitoring for MSPs
Your clients' websites often belong to someone else: a web agency, a marketing contractor, the owner's nephew. The domain still carries their email, so when it expires or an MX record changes, the ticket lands with you. The certificates on the public side of their network are the same story.
01 — What goes wrong
Where things usually go wrong
- 01
The domain is the email
An expired domain doesn't just take the website down. Mail stops arriving, and the client finds out from a supplier who can't reach them.
- 02
Registrar accounts in the wrong name
The domain was registered by an employee who left three years ago, with their personal email as the contact. Every renewal reminder since then has gone nowhere.
- 03
Certificates you install by hand
Remote access portals, webmail and other public HTTPS services often use certificates someone installs manually. From 15 March 2026 those last at most 200 days, falling to 47 days in 2029.
- 04
DNS changes nobody announced
A marketing tool asks the client to change nameservers, or a new provider rewrites the MX records. You hear about it when mail flow breaks.
02 — What helps
What matters most for you
- Domain expiry and registry statuses
- A daily RDAP lookup per domain: expiry date, registrar, nameservers and statuses such as transfer lock, pending delete and redemption.
- DNS change alerts
- We record NS, A, AAAA, MX and CAA records and alert when any of them change, so an edit made by someone else reaches you the same day.
- Any public HTTPS hostname
- Certificate checks every 6 hours on whatever answers HTTPS publicly: expiry, issuer, SANs, chain and hostname match. Web servers, portals and webmail alike.
- Into your existing tools
- Alerts in Microsoft Teams, Slack or email; signed webhooks for Zapier, Make or n8n if you want tickets raised automatically; a REST API and an MCP server for everything else.
- 47-day readiness per client
- A readiness score per client showing which certificates are automated and which will need a person as lifetimes shrink. Agency Pro covers 1,000 domains for $79/month.
03 — Practical notes
Start with an inventory
Before any tool, build one list per client. It is dull work and it pays for itself the first time a domain nearly lapses.
- Every registered domain, including the old brand names and typo domains the client bought years ago.
- The registrar for each, and whose email address is the account contact. Check it is not a former employee.
- Every public HTTPS hostname. The subdomain certificate finder reads Certificate Transparency logs, which record certificates issued for the client's domains by anyone, including the web agency.
- For each certificate: automated (ACME) or installed by hand, and who does it.
The domain expiry checker gives you the registrar, expiry date and statuses for a domain in one lookup. Our guide to domain expiry monitoring explains what statuses such as redemption and pending delete mean for recovery.
Why the 47-day schedule hits MSPs hardest
| From | Maximum certificate lifetime |
|---|---|
| 15 March 2026 | 200 days |
| 15 March 2027 | 100 days |
| 15 March 2029 | 47 days |
Web hosts mostly automated years ago. Appliances and hand-built servers often didn't. A certificate you replace once a year today will need replacing roughly eight times a year by 2029. The 47-day readiness checker shows which of a client's hostnames are already on automated issuance, and the 47-day guide covers the options for the rest.
Watch DNS as closely as expiry
Most outages we see in this space are changes, not expiries: an MX record rewritten by a new tool, nameservers moved during a website rebuild, a CAA record added without the CA your appliances use. ExpiryOwl records NS, A, AAAA, MX and CAA records and tells you when they change, so you can ask the question before the client does.
Start with five domains, free.
The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.