Alerts & notifications

What triggers a certificate alert and when: per-domain expiry thresholds, health changes, re-issue detection and unreachable hosts, by e-mail or webhook.

CertWatchr sends five kinds of alert, by e-mail and (on Pro) by webhook.

Alert kinds

Alert When you get it
Expiry warning The certificate has your alert threshold or fewer days left (30 on Free, your choice on a paid plan).
Expiry critical 7 days or fewer left. Marked as urgent.
Certificate changed The certificate served on the port is a different one from last time — a renewal, a re-issue, or something you did not expect.
Check error The host could not be reached or the TLS handshake failed, and retrying over about half an hour did not help.
New certificate in CT log (Starter and Pro) A certificate you have not seen before was issued for the hostname. See CT log monitoring.

Every alert names the domain, its label and what was found, and links to the domain's page.

How you receive them

E-mail

On from the start, to your account address. Turn it off or on under Settings → Notifications.

Webhook (Pro)

Set a Webhook URL under Settings → Webhooks and every alert is also posted there — as plain JSON, or formatted for Slack or Microsoft Teams. See Webhooks.

One alert per day, not one per check

Certificates are checked at least daily, and a warning would otherwise arrive on every check. So after an alert is sent, the same kind of alert for the same domain on the same channel is held back for 24 hours. You get one warning a day per domain until you fix it, not a stream.

For CT log alerts, the message tells you how many new certificates appeared during that day, so nothing is hidden by the collapse.

Snoozing a domain

Sometimes the warning is right and you already know — the renewal is booked, the server is being migrated next week. On the domain's page, Snooze alerts mutes every alert for that one domain for 1, 7, 14 or 30 days. To end it early, click Unsnooze.

  • Checks keep running. Status, days remaining and the health score stay current; only the notifications stop. A snoozed domain shows a muted bell in the list.
  • The snooze ends by itself — and it ends early if the certificate changes, since a renewal is usually what you were waiting for. You then get the "certificate changed" alert as normal.
  • The first alert after a snooze goes out immediately on the next check; the 24-hour spacing does not carry over.

There is deliberately no way to switch alerts off for a domain permanently. If you never want to hear about a host, remove it.

Summary e-mail

Separate from the alerts above, you can have a roll-up of everything you monitor: how many domains are OK, warning, critical or in error; which certificates expire soon; and the alerts sent in the period. Turn it on under Settings → Notifications → Summary e-mail:

  • Every day: covering the last 24 hours.
  • Once a week: sent on Monday, covering the last 7 days.
  • Don't send one: the default.

No summary is sent while you have no domains.

Alert history

Alerts in the top navigation lists every alert sent to you, newest first, across all your domains: when, which domain, the kind, the channel, and whether delivery succeeded. A failed webhook shows the HTTP status and error it got. Filter by domain, kind, channel or result; each domain's page also links to its own slice of the history.

If alerts are not arriving

  1. Check the e-mail address on Account and look in your spam folder.
  2. Make sure e-mail alerts are on under Settings → Notifications.
  3. Open Alerts. If the alert is listed, it was sent — the problem is on the receiving side. If it is not, the certificate may not have crossed the threshold yet, or the domain is snoozed.
  4. Still nothing? Contact support.