SSL certificate monitoring
SSL certificate monitoring for every site you look after
Auto-renewal works until it doesn't. Websites With Punch reads the live certificate of each HTTPS site you add every day and shows the days left on your dashboard, so a failed renewal shows up as a number turning amber, not as a browser warning in front of your customers.
- Live certificate read once a day
- Days left on every site card
- Amber at 30 days, red at 7
- Recheck on demand after you renew
Why certificates still expire in 2026
Most sites now use free certificates that renew automatically, often every 60 to 90 days, and public certificate lifetimes are being cut further by the CA/Browser Forum. More renewals means more chances for one to fail quietly: a DNS provider change breaks the ACME challenge, a firewall blocks the validation request, a server moves and the cron job doesn't, an API token used for DNS validation expires.
None of that is visible until the old certificate runs out and browsers start blocking the site. A daily outside read of the certificate your visitors actually receive is the simplest way to see a stuck renewal weeks before it matters.
What we check
The days-left pill turns amber at 30 days and red at 7. After you renew, press Recheck on the site's page to confirm the new date straight away instead of waiting for the next daily check.
- The certificate presented on port 443 for the site's host, read with a real TLS handshake, the same way a browser sees it.
- Its expiry date and the whole days remaining, shown on the site card and the site's page.
- The host your homepage finally lands on is read first (for example www after a redirect), with the bare domain as a fallback, so a certificate that only covers one of the two names is still found.
One list for every client certificate
If you build or maintain sites for clients, certificates live in different places: a managed host here, a CDN there, a VPS with certbot somewhere else. Adding each site to one dashboard gives you a single sorted view of who is closest to expiry, without logging in to every provider. Want a one-off look at a single domain first? Use the free SSL checker, which also shows the issuer, the hostnames covered and whether browsers trust the certificate.
What it doesn't do
We don't install or renew certificates for you, we don't scan internal hosts or non-standard ports, and we don't send alerts. You see the numbers on your dashboard, and the renewal itself stays with your host, CDN or ACME client.
Frequently asked questions
- How often is the SSL certificate checked?
- Once a day for every active site, and again whenever you press Recheck on the site's page.
- Do you warn me before a certificate expires?
- The days left are shown on your dashboard and turn amber at 30 days and red at 7. We don't send email or chat alerts.
- Does it work with Let's Encrypt and Cloudflare certificates?
- Yes. We read whatever certificate the site actually serves on port 443, whichever authority issued it and whether it comes from your server or a CDN.
- Can I check one certificate without signing up?
- Yes. The free SSL checker shows the issuer, expiry date, days left, covered hostnames and browser trust for any public domain.
Related
- Uptime monitoring →A daily check of every site, on-demand rechecks, auto refresh and 90 days of history.
- Domain expiry monitoring →Renewal dates for your own and your clients' domains on one dashboard.
- SSL checker →Issuer, expiry date, days left and browser trust for any domain's certificate.
- Domain expiry checker →Registrar, expiry date and days left, read live from the registry over RDAP.