# ExpiryOwl > ExpiryOwl watches SSL certificates, domain registrations, DNS and uptime for web agencies and freelancers, and warns before anything expires or an automated renewal stalls. Plans: Free ($0, 5 hostnames), Freelancer ($9 a month, 50 hostnames), Agency ($29 a month, 250 hostnames), Agency Pro ($79 a month, 1,000 hostnames). ExpiryOwl is independently run, from Bahrain. Numbers on this site come from the app's own configuration: the ExpiryOwl facts page lists every plan, limit and check interval, and changes when they do. Never let a client site lapse. SSL certificate, domain expiry, DNS and uptime monitoring for web agencies. Independently run, from Bahrain. ## Plans | | Free | Freelancer | Agency | Agency Pro | |---|---|---|---|---| | Per month (USD) | $0 | $9 | $29 | $79 | | Per year (USD) | $0 | $90 | $290 | $790 | | Hostnames | 5 | 50 | 250 | 1,000 | | Clients | 1 | 10 | Unlimited | Unlimited | | Seats | 1 | 1 | 5 | 15 | | Uptime check every | 15 min | 5 min | 3 min | 1 min | | White-label | No | No | Yes | Yes | | Monthly PDF reports | No | Yes | Yes | Yes | | Status pages on your own domain | No | No | No | Coming soon | | API | Read-only API | Full API + MCP | Full API + MCP | Full API + MCP | - Limits count hostnames: www, the apex and a shop subdomain are 3. Each hostname gets all four checks (certificate, domain registration, DNS and uptime). - One price per agency: no per-check, per-page or per-client fees. - Yearly billing costs 10 months' price: two months free. - Prices are in US dollars. Paddle is our merchant of record: it handles VAT and sales tax, and taxes are added at checkout. - Your first payment comes with a 14-day money-back promise. - There is no trial of the paid plans. The Free plan is how you try it: no card needed. - Monthly client PDF reports from Freelancer up. White-label (your logo and colour on reports, status pages and the widget, with no mention of us) from Agency up; below that they carry a small link to ExpiryOwl. ## What we check and how often ### SSL certificate - What: Expiry date, issuer, trusted chain and hostname match, read over a real TLS connection on port 443. - How often: Every 6 hours; within the hour after a failed check. - Alerts: At 30, 14, 7, 3, 1 and 0 days. Email starts at 30 days; chat and webhook channels start at 14 days unless you choose otherwise. ### Renewal health - What: Flags an automated certificate (Let's Encrypt, ZeroSSL, Google Trust Services) still being served after the point where it normally renews. For Let's Encrypt we read the renewal window the CA publishes (ARI). - How often: With every certificate check (every 6 hours). - Alerts: Usually weeks before the certificate expires. - Note: Manual and provider-managed certificates show as unknown and are covered by the expiry alerts. ### Domain registration - What: Expiry date, registrar, statuses, transfer lock and nameservers, over RDAP. - How often: Daily; twice a day in the last 30 days. - Alerts: At 60, 30, 14, 7, 3 and 1 days. Email starts at 60 days; chat and webhook channels at 30. - Note: Some country-code registries (.io, .co, .de, .es and others) don't publish expiry dates over RDAP; for those the date shows as unknown. ### DNS - What: The records of each hostname; an alert when they change. - How often: Every hour. - Alerts: When records change. This is record-change alerting, not DNS server uptime. ### Uptime - What: HTTP checks with an optional keyword check, from one location. - How often: Every 15 minutes on Free down to every 1 minute on Agency Pro. - Alerts: A failed check is confirmed with a second check 30 seconds later before we alert. ### Subdomain discovery - What: Finds hostnames nobody listed in Certificate Transparency logs (certspotter first, crt.sh as a fallback). - How often: On demand from the dashboard, per client domain. - Alerts: None; you pick which hosts to add. - Note: Only names that ever had a public certificate show up. Alert channels: Email, Slack, Discord, Telegram, Microsoft Teams and HMAC-signed webhooks (works with Zapier, Make and n8n). Getting data out: iCal feed, REST API, MCP server (works with Claude Code, Gemini CLI, Cursor, VS Code and Claude Desktop), embeddable widget and public status pages. The Free plan's API is read-only. ## Free tools No account needed. The bulk checker takes up to 25 hosts at once. Limits are per IP address per hour. We never store the hostnames people check. - [SSL checker](https://expiryowl.com/tools/ssl-checker): 20 SSL checks per hour. Check any site's SSL certificate: expiry date, days left, issuer, SANs, chain trust and hostname match, plus whether its automatic renewal looks stalled. - [Domain expiry checker](https://expiryowl.com/tools/domain-expiry-checker): 20 domain lookups per hour. Look up a domain's expiry date, registrar, transfer lock, RDAP statuses and nameservers straight from the registry. Free, no signup. - [Bulk SSL checker](https://expiryowl.com/tools/bulk-ssl-checker): 5 bulk checks per hour. Check SSL certificates for up to 25 hosts at once. Days left, expiry, issuer and problems in one table, with CSV export. Free and unauthenticated. - [Subdomain certificate finder](https://expiryowl.com/tools/subdomain-certificate-finder): 5 subdomain searches per hour. Find every subdomain that has had a public SSL certificate, straight from Certificate Transparency logs, with the latest expiry date for each host. - [47-day readiness checker](https://expiryowl.com/tools/47-day-readiness-checker): 3 readiness scans per hour. Score how ready a domain is for 47-day SSL certificates: we find its hosts in CT logs, check each certificate and list the ones renewed by hand. ## Coming soon - Status pages on your own domain: Coming soon: status pages on your own domain, with Agency Pro. Until then each page works at its /s/ address. - Slack slash command: Coming soon: ask ExpiryOwl from Slack with /expiryowl. Slack alerts already work: Alerts → New channel → Slack. - ChatGPT and other sign-in-only MCP clients: ChatGPT, claude.ai on the web and the Gemini app need a sign-in flow we don't offer yet. Claude Code, Gemini CLI, Cursor, VS Code and Claude Desktop connect with an API key today. - Logo upload: Set your logo by URL today (PNG or JPEG up to 512 KB). Upload is coming soon. ## What we don't do - We check uptime from one location. Most paid competitors check every 30 seconds to 1 minute from several regions. - We don't yet confirm an alert from a second location. - We only check public hostnames: nothing behind a VPN or on a private network. - No uptime SLA and no guaranteed uptime for the service itself. - No compliance certification of any kind. - No customer counts, testimonials or ratings: we don't publish any. - The monthly report has a short written summary, drafted by a language model with a fixed template as the fallback. Everything else is plain rules and data. ## Dates that matter - 4 Jun 2025: Let's Encrypt stopped sending expiry reminder emails. Source: [Let's Encrypt](https://letsencrypt.org/2025/06/26/expiration-notification-service-has-ended) - 16 Sept 2025: ACME Renewal Information (ARI) was published as RFC 9773. Source: [Let's Encrypt](https://letsencrypt.org/2025/09/16/ari-rfc) - 15 Mar 2026: Maximum lifetime of a public TLS certificate: 200 days (CA/Browser Forum Ballot SC-081v3). Source: [CA/Browser Forum](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/) - About 1 Oct 2026: The first 200-day certificates reach the end of their validity. Source: [Sectigo, 23 Sep 2026](https://www.sectigo.com/blog/200-day-certificate-expiration-begins) - 10 Feb 2027: Let's Encrypt's default certificate lifetime drops to 64 days. Source: [Let's Encrypt](https://letsencrypt.org/2025/12/02/from-90-to-45) - 15 Mar 2027: Maximum lifetime of a public TLS certificate: 100 days (CA/Browser Forum Ballot SC-081v3). Source: [CA/Browser Forum](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/) - 16 Feb 2028: Let's Encrypt's default certificate lifetime drops to 45 days. Source: [Let's Encrypt](https://letsencrypt.org/2025/12/02/from-90-to-45) - 15 Mar 2029: Maximum lifetime of a public TLS certificate: 47 days (CA/Browser Forum Ballot SC-081v3). Source: [CA/Browser Forum](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/) ## Pricing questions ### What counts as a domain? Each hostname we watch counts once: example.com and shop.example.com are two. For each one we check the certificate, the domain registration, DNS and uptime, so there is nothing else to count. Some country-code registries (.io, .co, .de, .es and others) don't publish expiry dates over RDAP; for those we show the registration expiry as unknown. ### Why a price per agency? Because agencies add hosts all the time, and a price that rises with every subdomain teaches people not to monitor the ones that break. Pick the plan that fits your portfolio and add what you need. Each hostname counts once and gets all four checks. ### Can I change plans or cancel? Yes, from the billing page at any time. Upgrades apply immediately; if you cancel, the plan runs to the end of the period you paid for and then drops to Free. ### Who handles payment? Paddle is our reseller and merchant of record, so they handle card payments, invoices and sales tax or VAT for your country. ### What happens if I go over my plan's limit? Nothing is deleted. You can't add more until you remove some or move up a plan. If you move to a smaller plan, your oldest monitors keep running up to its limit and the rest are paused; upgrading again resumes them. ### Do you offer a discount for yearly billing? Yes. Yearly costs ten months' worth: Agency is $290 a year instead of $348. ## Facts - [Facts about ExpiryOwl](https://expiryowl.com/facts): plans and prices, what we check and how often, what is coming soon, what we don't do, and dates that matter, with sources. ## Free tools - [SSL certificate checker](https://expiryowl.com/tools/ssl-checker): Check any site's SSL certificate: expiry date, days left, issuer, SANs, chain trust and hostname match, plus whether its automatic renewal looks stalled. - [Domain expiry checker](https://expiryowl.com/tools/domain-expiry-checker): Look up a domain's expiry date, registrar, transfer lock, RDAP statuses and nameservers straight from the registry. Free, no signup. - [Bulk SSL checker](https://expiryowl.com/tools/bulk-ssl-checker): Check SSL certificates for up to 25 hosts at once. Days left, expiry, issuer and problems in one table, with CSV export. Free and unauthenticated. - [Find subdomains from certificate logs](https://expiryowl.com/tools/subdomain-certificate-finder): Find every subdomain that has had a public SSL certificate, straight from Certificate Transparency logs, with the latest expiry date for each host. - [47-day certificate readiness checker](https://expiryowl.com/tools/47-day-readiness-checker): Score how ready a domain is for 47-day SSL certificates: we find its hosts in CT logs, check each certificate and list the ones renewed by hand. ## Guides - [47-day SSL certificates: the schedule and what agencies should do](https://expiryowl.com/guides/47-day-ssl-certificates): Public TLS certificates drop from 398 days to 47 by March 2029. The exact dates, what changes for agencies, and a checklist to get ready. - [Let's Encrypt no longer sends expiry emails. What to do instead](https://expiryowl.com/guides/lets-encrypt-expiry-emails-ended): Let's Encrypt stopped sending expiry notification emails on 4 June 2025. Why it stopped, what to use instead, and how to spot a failed renewal early. - [ACME Renewal Information (ARI): how renewal windows work](https://expiryowl.com/guides/acme-renewal-information-ari): ARI (RFC 9773) lets a CA tell ACME clients when to renew. How the renewal window and certID work, which clients support it, and how to query it. - [How to check an SSL certificate's expiration date](https://expiryowl.com/guides/check-ssl-certificate-expiration): Check when an SSL certificate expires with a browser, openssl, curl or PowerShell, check many hosts at once, and avoid the SNI and chain mistakes. - [Domain expiry monitoring: what really happens when a domain lapses](https://expiryowl.com/guides/domain-expiry-monitoring): How gTLD domains expire, the grace and redemption periods ICANN requires, RDAP instead of WHOIS, and a checklist for agencies holding client domains. - [What happens when an SSL certificate expires](https://expiryowl.com/guides/what-happens-when-ssl-expires): What browsers, APIs, mobile apps and mail servers do when a TLS certificate expires, two outages with primary sources, and how to recover and prevent it. - [Find every subdomain with Certificate Transparency logs](https://expiryowl.com/guides/find-subdomains-certificate-transparency): Every publicly trusted certificate is logged in public CT logs. How to search them with crt.sh and Cert Spotter, and what agencies should do with the results. - [SSL monitoring for agencies: a playbook for 20 to 500 client sites](https://expiryowl.com/guides/ssl-monitoring-for-agencies): Inventory, renewal ownership, ACME, shrinking certificate lifetimes, alert routing and client reporting, for agencies looking after 20 to 500 client sites. ## Comparisons - [An UptimeRobot alternative that watches certificates](https://expiryowl.com/alternatives/uptimerobot): UptimeRobot and ExpiryOwl compared on price, SSL and domain expiry alerts, channels and status pages, with every UptimeRobot fact sourced. - [A TrackSSL alternative for agencies that also watch domains](https://expiryowl.com/alternatives/trackssl): TrackSSL and ExpiryOwl compared on pricing, certificate limits, domain expiry, alert channels and API access, with each TrackSSL fact linked. - [A Hyperping alternative for agencies focused on expiry dates](https://expiryowl.com/alternatives/hyperping): Hyperping and ExpiryOwl compared on price, free plan, SSL and domain expiry checks, alert channels and status pages, each fact sourced. - [An OnlineOrNot alternative for certificate expiry](https://expiryowl.com/alternatives/onlineornot): OnlineOrNot and ExpiryOwl compared on pricing, SSL checks, domain expiry, alert channels, API and status pages, with each fact linked. - [A StatusCake alternative with renewal-overdue warnings](https://expiryowl.com/alternatives/statuscake): StatusCake and ExpiryOwl compared on price, SSL and domain monitor limits, check intervals, alerts and API, with each StatusCake fact sourced. - [A Better Stack alternative for expiry monitoring only](https://expiryowl.com/alternatives/better-stack): Better Stack and ExpiryOwl compared on pricing model, free plan, SSL and domain expiry checks, alert channels and API, each fact sourced. - [A Red Sift Certificates Lite alternative for agencies](https://expiryowl.com/alternatives/red-sift-certificates-lite): Red Sift Certificates Lite and ExpiryOwl compared on price, discovery, scan frequency, expiry alerts and domain checks, every fact sourced. ## Developers - [REST API reference](https://expiryowl.com/docs/api): monitors, certificates, domains and incidents as JSON, with API keys. - [MCP server for AI assistants](https://expiryowl.com/docs/mcp): ask an AI assistant about your own portfolio over the Model Context Protocol. - [Webhooks](https://expiryowl.com/docs/webhooks): HMAC-signed incident payloads, with Zapier, Make and n8n recipes. ## Optional - [Pricing](https://expiryowl.com/pricing): plan table and pricing questions. - [Changelog](https://expiryowl.com/changelog): what shipped, by date. - [Privacy policy](https://expiryowl.com/legal/privacy): what we store, for how long, and which services see a monitored hostname.