SSL certificate monitoring
that warns you before expiry
CertWatchr watches every hostname and port you look after: your own products, your customers, and every project in between. It scores how healthy each certificate really is, and tells you by e-mail or webhook long before a browser tells your customers.
- 3 domains free, forever
- No credit card
- Read-only checks, no agent to install
Why certificate monitoring matters
A certificate fails in three ways, and each one stays invisible until somebody else runs into it. CertWatchr watches for all three, not only the first.
It quietly expired
The renewal reminder went to someone who left. Every visitor now sees a full-page browser warning. Expiry checks and per-domain thresholds catch it weeks ahead.
It works for you, not for everyone
An incomplete chain, a missing SAN, TLS 1.0 still enabled. The handshake succeeds for you and fails for someone else. The health score is explicit about why.
Someone else issued it
A team spun up a certificate outside your process, or a CA mis-issued one for your domain. A check on :443 can never see that. A CT log can.
Full-featured SSL/TLS certificate monitoring
Not just days remaining.
A health score that explains itself
Every check produces a 0–100 score from eight explicit sub-checks, stored per check so you can chart it over time and see a configuration change land.
Certificate Transparency monitoring
Public logs record every certificate a trusted CA issues. CertWatchr polls them for your hostnames and raises an alert when one appears that it hasn't seen before, mis-issuance and shadow IT included.
A burst of new certificates collapses into a single notification listing the serials.
Alerts that don't flood
E-mail and webhooks, in JSON or formatted natively for Slack and Teams. The same alert for the same domain is suppressed within a cooldown window, so one broken host can't fill your inbox overnight.
Any host, any TLS port
Not only :443. Mail servers, internal APIs and services on custom ports are checked the same way, with readable causes (DNS failure, refused, handshake failure) instead of raw exceptions.
Re-issue detection
A changed fingerprint raises an alert even when the new certificate is perfectly valid, which is how you notice a renewal nobody told you about.
REST API and CSV
List, add, delete and check domains from your own tooling with a rotatable token. Bulk import and export by CSV, so a migration is one upload.
Organised by customer and project
Tag every domain — prod, web, customer-a, staging — and filter the list instantly. A flat list of hostnames stops being readable the moment it mixes your own products with someone else's.
Schedules and summaries
Daily, weekly, or a cron expression per domain. Add an optional daily or weekly summary e-mail if you'd rather read one message than watch a dashboard.
Nothing to install
No private keys, no server access, no agent. Your account can be protected with authenticator-app two-factor and recovery codes.
Start monitoring certificates in about a minute
Three steps, and the watching is ours from then on.
Create an account
E-mail and a password. No card, and the free tier stays free.
Add your hostnames
One at a time or by CSV. Pick a port, a check schedule and how many days ahead you want to be warned.
Hear it from us first
Expiry, health drops, unexpected re-issues and new certificates in CT logs land in your inbox or your webhook.
Hosted in the EU. Nothing to hand over.
Monitoring a certificate does not need access to the server it sits on. A certificate is public, sent to everyone who connects, so the check reads what any visitor already receives and nothing else.
How we handle your dataEU infrastructure
Servers and database in Germany, with Hetzner Online GmbH named in our privacy policy rather than described in the abstract.
No private keys, ever
Read-only TLS handshakes. No agent to install, no credentials to share, nothing left behind if you leave.
No trackers, no CDNs
No analytics, no ad pixels, and not a single font or script fetched from anyone else's servers.
Two-factor, Argon2
Authenticator-app 2FA with encrypted secrets and recovery codes; passwords hashed with Argon2.
Start free, upgrade when you outgrow it
Monthly prices below. Paying yearly saves 20%.
Free
For a handful of domains you own personally.
forever
- Up to 3 domains
- Daily expiry checks
- E-mail alerts and summaries
- No health score or CT monitoring
Starter
RecommendedFor the person who owns the certificates.
per month
- Up to 50 domains
- Certificate health score
- Certificate Transparency monitoring
- REST API access
Pro
For a fleet, and for piping alerts into your tools.
per month
- Unlimited domains
- Everything in Starter
- Webhooks, including Slack and Teams
- Per-domain custom check schedules
Questions people actually ask
example.com and example.com:8443 count as two monitored domains.
More detail in the documentation, or ask us directly.
Find out before your customers do
Add your first hostname in under a minute. 3 domains stay free for as long as you want them.