For web design agencies

SSL and domain expiry monitoring for web design agencies

You built the site two years ago, the client owns the domain, the host is whoever was cheapest that year, and nobody remembers who gets the renewal emails. When the certificate lapses or the domain expires, the client calls you anyway. We built this so that call happens less often.

Start free5 domains, no card.

01 — What goes wrong

Where things usually go wrong

  1. 01

    Forty clients, forty setups

    Some sites sit on your hosting, some on the client's, a few on hosts you have never logged into. There is no single place that tells you which certificate expires next.

  2. 02

    The domain is in the client's name

    The client registered it with a personal card at a registrar you can't see. The card expires, auto-renew fails, and the reminders go to an inbox nobody reads.

  3. 03

    Auto-renewal that quietly stopped

    Automated certificates renew themselves until a DNS change, a host migration or a firewall rule stops them. The old certificate keeps working for weeks after that, which is exactly why nobody notices.

  4. 04

    Care plans with nothing to show

    Clients pay for maintenance and see nothing. Proving that the boring things are fine takes time you don't bill for.

02 — What helps

What matters most for you

Clients, not a flat list of monitors
Group hostnames by client and see each client's next expiry at a glance. Agency is $29/month for 250 domains and unlimited clients.
Renewal overdue, weeks before expiry
ACME certificates (Let's Encrypt, ZeroSSL, Google Trust Services) normally renew when about a third of their lifetime remains. When one passes that point without renewing, we flag it as renewal overdue, usually weeks before it expires. For Let's Encrypt we read its ACME Renewal Information window.
Domain expiry from the registry
A daily RDAP lookup per domain: expiry date, registrar, nameservers and statuses such as transfer lock, pending delete and redemption.
Monthly reports the client can read
A white-label monthly PDF per client with a short written summary, from Freelancer ($9/month) up.
Status pages under your name
White-label client status pages on Agency, on the client's own domain on Agency Pro ($79/month).

03 — Practical notes

A monthly check you can do this afternoon

You don't need a tool to start. You need a list, and most agencies don't have one. Here is the version we would keep in a spreadsheet if we were you.

  1. Write down every hostname you are responsible for: the apex, www, staging, the shop, the old microsite. The subdomain certificate finder reads Certificate Transparency logs and usually turns up a few you forgot.
  2. Paste the list into the bulk SSL checker and note the expiry date and issuer of each certificate.
  3. Run each registered domain through the domain expiry checker and note the registrar and the expiry date.
  4. For every domain, write down who holds the registrar login. If the answer is "the client, probably", that is the risk.
What to record per hostname
ColumnWhy it matters
IssuerLet's Encrypt, ZeroSSL and Google Trust Services certificates renew automatically. Anything else is renewed by a person.
Days leftAn automated certificate with less than a third of its life left has probably missed a renewal.
Registrar and login ownerTells you who to chase when the renewal card fails.
NameserversA change here means someone moved DNS, and the certificate may be next.

Decide who owns what, in writing

Most expiry incidents we hear about are ownership problems, not technical ones. Put one line per client in your care plan: who pays for the domain, who holds the registrar account, and who is told when something is about to lapse. It saves an awkward conversation later.

Certificates are about to get shorter

Under CA/B Forum Ballot SC-081v3, the maximum certificate lifetime drops to 200 days from 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029. Any client still on a hand-installed yearly certificate will need a different plan. Our guide to 47-day certificates covers what to change, and SSL monitoring for agencies covers how to watch a few hundred sites without reading every alert.

When the spreadsheet gets tedious, ExpiryOwl does the same checks on a schedule: certificates every 6 hours, domains daily, alerts at 30, 14, 7, 3, 1 and 0 days. The first 5 domains are free, no card.

Start with five domains, free.

The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.