For WordPress agencies

Certificate and domain monitoring for WordPress agencies

Most of your client sites run on shared or managed WordPress hosting, with a free certificate the host renews for you. That works until the client moves hosts, points DNS somewhere new for an email provider, or lets the card behind the domain expire. Then the first person to notice is a visitor staring at a browser warning.

Start free5 domains, no card.

01 — What goes wrong

Where things usually go wrong

  1. 01

    AutoSSL stops after a DNS change

    On cPanel hosting, AutoSSL issues free certificates (Let's Encrypt by default) and renews them during its nightly runs. cPanel's SSL/TLS status page lists a domain that no longer resolves as an AutoSSL problem. The warning sits in a cPanel account the client never opens.

  2. 02

    Let's Encrypt stopped emailing you

    Let's Encrypt ended its expiry notification emails on 4 June 2025. If those emails were your safety net, you no longer have one. More in our guide.

  3. 03

    The client's card expired

    The domain was on auto-renew with the client's card. The card was replaced, the renewal failed, and the domain is now working its way through the registry's grace and redemption statuses.

  4. 04

    Staging sites nobody switched off

    staging.client.com from the last rebuild, still answering, with a certificate that expired in March. Nobody remembers it exists until a client clicks an old link.

02 — What helps

What matters most for you

Renewal overdue, before it becomes expired
ACME certificates (Let's Encrypt, ZeroSSL, Google Trust Services) normally renew when about a third of their lifetime remains. When one passes that point without renewing, we flag it as renewal overdue, usually weeks before it expires. For Let's Encrypt we read its ACME Renewal Information window.
Subdomain discovery
We read Certificate Transparency logs for each client domain and list the hostnames that have had certificates, including the staging site from 2023.
Domain expiry and registry statuses
A daily RDAP lookup per domain: expiry date, registrar, nameservers and statuses such as transfer lock, pending delete and redemption.
Alerts where your team already is
Email, Slack, Microsoft Teams, Discord or Telegram, at 30, 14, 7, 3, 1 and 0 days. Signed webhooks if you want them in your helpdesk via Zapier, Make or n8n.
Care plan reports
A white-label monthly PDF per client with a short written summary, from Freelancer ($9/month) up. It is the part of the care plan the client actually sees.

03 — Practical notes

Where your certificates come from

WordPress itself doesn't care where the certificate comes from. The host does, and each setup fails in its own way.

Common WordPress certificate setups
SetupWho renewsWhat usually breaks it
cPanel with AutoSSLThe host, nightlyThe hostname no longer resolves to the server, or a CAA record that leaves out the issuing CA
Managed WordPress hostThe hostDNS moved to a new provider or proxy without anyone telling the host
Certificate bought and installed by handYou, on a date someone wrote downThe date. From 15 March 2026 these last at most 200 days

A CAA record lists which certificate authorities may issue for a domain. Add one for a new provider and forget Let's Encrypt, and Let's Encrypt can no longer issue for that domain. The current certificate keeps working, so nothing looks wrong for weeks.

A checklist for every migration

  1. After the DNS switch, check the apex and www with the SSL checker. Both should show the new host's certificate.
  2. Check the issuer. If it changed, make sure any CAA record allows the new one.
  3. Run the subdomain certificate finder and decide what to do with every old hostname: move it, redirect it or delete the DNS record.
  4. Look up the domain in the domain expiry checker and confirm who pays for it. Migrations are a good moment to ask.
  5. Come back in a few weeks. The real test is the first renewal on the new host, not the first certificate.

Why we watch renewals, not only expiry

A free certificate that fails to renew still has weeks of life left. An alert at 7 days works, but it leaves you debugging a host's renewal under pressure. We flag the missed renewal instead, which is usually the first sign that a migration or DNS edit went wrong. Our guide on what happens when SSL expires explains what visitors see if nobody catches it. ExpiryOwl starts free for 5 domains.

Start with five domains, free.

The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.