For web design agencies
SSL and domain expiry monitoring for web design agencies
You built the site two years ago, the client owns the domain, the host is whoever was cheapest that year, and nobody remembers who gets the renewal emails. When the certificate lapses or the domain expires, the client calls you anyway. We built this so that call happens less often.
01 — What goes wrong
Where things usually go wrong
- 01
Forty clients, forty setups
Some sites sit on your hosting, some on the client's, a few on hosts you have never logged into. There is no single place that tells you which certificate expires next.
- 02
The domain is in the client's name
The client registered it with a personal card at a registrar you can't see. The card expires, auto-renew fails, and the reminders go to an inbox nobody reads.
- 03
Auto-renewal that quietly stopped
Automated certificates renew themselves until a DNS change, a host migration or a firewall rule stops them. The old certificate keeps working for weeks after that, which is exactly why nobody notices.
- 04
Care plans with nothing to show
Clients pay for maintenance and see nothing. Proving that the boring things are fine takes time you don't bill for.
02 — What helps
What matters most for you
- Clients, not a flat list of monitors
- Group hostnames by client and see each client's next expiry at a glance. Agency is $29/month for 250 domains and unlimited clients.
- Renewal overdue, weeks before expiry
- ACME certificates (Let's Encrypt, ZeroSSL, Google Trust Services) normally renew when about a third of their lifetime remains. When one passes that point without renewing, we flag it as renewal overdue, usually weeks before it expires. For Let's Encrypt we read its ACME Renewal Information window.
- Domain expiry from the registry
- A daily RDAP lookup per domain: expiry date, registrar, nameservers and statuses such as transfer lock, pending delete and redemption.
- Monthly reports the client can read
- A white-label monthly PDF per client with a short written summary, from Freelancer ($9/month) up.
- Status pages under your name
- White-label client status pages on Agency, on the client's own domain on Agency Pro ($79/month).
03 — Practical notes
A monthly check you can do this afternoon
You don't need a tool to start. You need a list, and most agencies don't have one. Here is the version we would keep in a spreadsheet if we were you.
- Write down every hostname you are responsible for: the apex, www, staging, the shop, the old microsite. The subdomain certificate finder reads Certificate Transparency logs and usually turns up a few you forgot.
- Paste the list into the bulk SSL checker and note the expiry date and issuer of each certificate.
- Run each registered domain through the domain expiry checker and note the registrar and the expiry date.
- For every domain, write down who holds the registrar login. If the answer is "the client, probably", that is the risk.
| Column | Why it matters |
|---|---|
| Issuer | Let's Encrypt, ZeroSSL and Google Trust Services certificates renew automatically. Anything else is renewed by a person. |
| Days left | An automated certificate with less than a third of its life left has probably missed a renewal. |
| Registrar and login owner | Tells you who to chase when the renewal card fails. |
| Nameservers | A change here means someone moved DNS, and the certificate may be next. |
Decide who owns what, in writing
Most expiry incidents we hear about are ownership problems, not technical ones. Put one line per client in your care plan: who pays for the domain, who holds the registrar account, and who is told when something is about to lapse. It saves an awkward conversation later.
Certificates are about to get shorter
Under CA/B Forum Ballot SC-081v3, the maximum certificate lifetime drops to 200 days from 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029. Any client still on a hand-installed yearly certificate will need a different plan. Our guide to 47-day certificates covers what to change, and SSL monitoring for agencies covers how to watch a few hundred sites without reading every alert.
When the spreadsheet gets tedious, ExpiryOwl does the same checks on a schedule: certificates every 6 hours, domains daily, alerts at 30, 14, 7, 3, 1 and 0 days. The first 5 domains are free, no card.
Start with five domains, free.
The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.