Expiry, health and Certificate Transparency in one place

SSL certificate monitoring
that warns you before expiry

CertWatchr watches every hostname and port you look after: your own products, your customers, and every project in between. It scores how healthy each certificate really is, and tells you by e-mail or webhook long before a browser tells your customers.

  • 3 domains free, forever
  • No credit card
  • Read-only checks, no agent to install

Why certificate monitoring matters

A certificate fails in three ways, and each one stays invisible until somebody else runs into it. CertWatchr watches for all three, not only the first.

It quietly expired

The renewal reminder went to someone who left. Every visitor now sees a full-page browser warning. Expiry checks and per-domain thresholds catch it weeks ahead.

It works for you, not for everyone

An incomplete chain, a missing SAN, TLS 1.0 still enabled. The handshake succeeds for you and fails for someone else. The health score is explicit about why.

Someone else issued it

A team spun up a certificate outside your process, or a CA mis-issued one for your domain. A check on :443 can never see that. A CT log can.

Features

Full-featured SSL/TLS certificate monitoring

Not just days remaining.

A health score that explains itself

Every check produces a 0–100 score from eight explicit sub-checks, stored per check so you can chart it over time and see a configuration change land.

Chain & hostname40 / 40
Expiry19 / 25
Key & signature20 / 20
TLS version7 / 15

Certificate Transparency monitoring

Public logs record every certificate a trusted CA issues. CertWatchr polls them for your hostnames and raises an alert when one appears that it hasn't seen before, mis-issuance and shadow IT included.

A burst of new certificates collapses into a single notification listing the serials.

Alerts that don't flood

E-mail and webhooks, in JSON or formatted natively for Slack and Teams. The same alert for the same domain is suppressed within a cooldown window, so one broken host can't fill your inbox overnight.

Any host, any TLS port

Not only :443. Mail servers, internal APIs and services on custom ports are checked the same way, with readable causes (DNS failure, refused, handshake failure) instead of raw exceptions.

Re-issue detection

A changed fingerprint raises an alert even when the new certificate is perfectly valid, which is how you notice a renewal nobody told you about.

REST API and CSV

List, add, delete and check domains from your own tooling with a rotatable token. Bulk import and export by CSV, so a migration is one upload.

Organised by customer and project

Tag every domain — prod, web, customer-a, staging — and filter the list instantly. A flat list of hostnames stops being readable the moment it mixes your own products with someone else's.

Schedules and summaries

Daily, weekly, or a cron expression per domain. Add an optional daily or weekly summary e-mail if you'd rather read one message than watch a dashboard.

Nothing to install

No private keys, no server access, no agent. Your account can be protected with authenticator-app two-factor and recovery codes.

How it works

Start monitoring certificates in about a minute

Three steps, and the watching is ours from then on.

1

Create an account

E-mail and a password. No card, and the free tier stays free.

2

Add your hostnames

One at a time or by CSV. Pick a port, a check schedule and how many days ahead you want to be warned.

3

Hear it from us first

Expiry, health drops, unexpected re-issues and new certificates in CT logs land in your inbox or your webhook.

Security

Hosted in the EU. Nothing to hand over.

Monitoring a certificate does not need access to the server it sits on. A certificate is public, sent to everyone who connects, so the check reads what any visitor already receives and nothing else.

How we handle your data

EU infrastructure

Servers and database in Germany, with Hetzner Online GmbH named in our privacy policy rather than described in the abstract.

No private keys, ever

Read-only TLS handshakes. No agent to install, no credentials to share, nothing left behind if you leave.

No trackers, no CDNs

No analytics, no ad pixels, and not a single font or script fetched from anyone else's servers.

Two-factor, Argon2

Authenticator-app 2FA with encrypted secrets and recovery codes; passwords hashed with Argon2.

Pricing

Start free, upgrade when you outgrow it

Monthly prices below. Paying yearly saves 20%.

Free

For a handful of domains you own personally.

€0

forever

  • Up to 3 domains
  • Daily expiry checks
  • E-mail alerts and summaries
  • No health score or CT monitoring
Sign up free

Pro

For a fleet, and for piping alerts into your tools.

€9.99

per month

  • Unlimited domains
  • Everything in Starter
  • Webhooks, including Slack and Teams
  • Per-domain custom check schedules
Compare plans
FAQ

Questions people actually ask

It opens a normal TLS handshake to the host and port you enter, exactly as a browser does, and reads the certificate the server presents. The check is read-only: no agent, no private key, no credentials, nothing installed on your side.

Expiry checks run every 24 hours, and each domain can be set to daily, weekly, or (on Pro) a custom cron schedule. Health scores are recalculated every 30 minutes and Certificate Transparency logs are polled hourly. You can also trigger a check by hand at any time.

Yes, anything from 1 to 65535 that speaks TLS. IMAPS on 993, SMTPS on 465, an internal HTTPS service on a custom port. example.com and example.com:8443 count as two monitored domains.

You keep paid features until the end of the period you've already paid for, then drop to Free. Nothing is deleted. Domains over the Free limit stop being checked, and start again if you upgrade.

Yes. Every domain you add can carry tags — prod, web, customer-a, staging — and you can filter the dashboard by tag so you see only what belongs to a given customer or project. The search field looks across hostnames and labels, so finding a domain is fast even when you manage hundreds.

More detail in the documentation, or ask us directly.

Find out before your customers do

Add your first hostname in under a minute. 3 domains stay free for as long as you want them.