A full-page browser wall
The moment a certificate expires, Chrome, Safari and Firefox throw an interstitial security warning over your entire site. Visitors see red, not your homepage.
PulseStack connects to your site on port 443 and reads the live TLS certificate the same way a browser does, then warns you before it expires. One silent renewal failure is all it takes to replace your homepage with a full-page security warning. We make sure that day never arrives unannounced.
Free plan, no card required. SSL certificate insight is included from the Pro plan at £39/mo.
Live TLS handshake - the same inspection PulseStack repeats around the clock.
The port we connect to on every check, inspecting the live TLS certificate exactly as a browser does.
Certificate facts verified each run: days remaining, issuer, chain integrity and hostname match.
Fastest check interval on Enterprise. Starter, Pro and Team check every 60 seconds.
Native alert channels, so the expiry warning reaches you where you already work.
A certificate does not fail loudly. It fails at a timestamp, and the internet decides your site is dangerous. Here is what that actually looks like.
The moment a certificate expires, Chrome, Safari and Firefox throw an interstitial security warning over your entire site. Visitors see red, not your homepage.
Nobody types a card number into a page the browser has flagged as unsafe. Checkout, sign-up and lead forms all collapse to zero while the cert is expired.
Most certs are set to renew automatically. Most of the time they do. The one time the renewal cron fails silently is the time you find out from a customer, not a dashboard.
A valid leaf certificate served without its intermediate still fails in many clients. It works in your browser and breaks for a segment of real users you never see.
We do not just ping the port. We complete the TLS handshake and inspect the certificate exactly as a visitor's browser would, so what we report is what your users will actually experience.
We read the notAfter date and count down. You set a days-before-expiry threshold and we warn the moment it is crossed, not on the day it dies.
Who signed the certificate and the exact window it is valid for, surfaced on every check so an unexpected re-issue never slips past you.
We verify the chain resolves to a trusted root, catching the missing-intermediate mistakes that pass in your browser but fail for real visitors.
We confirm the hostname is covered by the certificate's subject and SANs, so a mismatch after a migration is caught before customers hit a warning.
Paste the domain you want watched. No agent, no DNS change, no code on your site.
Choose how many days before expiry you want to be warned. A fortnight, a month, whatever suits your renewal flow.
Route the warning to email, Slack, Teams, PagerDuty or any of the eight native channels.
PulseStack re-checks on your plan's interval and stays silent until something actually needs you.
Start on the free plan today and add certificate insight whenever you are ready. No card to begin.
Certificate health sits alongside every other check your site needs. Watch the whole stack from a single account, with HTTP and API checks supporting custom request headers.
Status codes, response time and content from any URL.
Confirm a word is present, or flag when one appears.
Reachability at the network layer for any host.
Watch a specific service port stays open and answering.
Endpoint checks with custom request headers.
Cron and background jobs check in, or you get told.
Records resolve to the values you expect.
Registration countdown, sibling to certificate watch.
SSL monitoring is part of the same platform that runs your uptime checks, SEO monitoring and the passive Security Shield. Everything below comes as standard on the plans that include certificate insight.
The Security Shield adds ten passive security tests and grades your site from A to F, giving certificate health context within your wider security posture.
A certificate alert is only useful if you see it in time. Route it to any of these, and use the consecutive-failure threshold to keep the noise down.
SMS and voice are an add-on, included on the Team and Enterprise plans.
Two of them rely on you remembering. One of them does not.
You manage certificates you did not buy on domains you did not register. One expired cert on a client site is one angry phone call. Watch every hostname from a single account.
Auto-renewal is set up and mostly works. This is your independent second pair of eyes, catching the silent cron failure and routing it straight to PagerDuty.
No dedicated ops person, no time to remember renewal dates. Point PulseStack at your domain and let the days-before-expiry warning do the remembering for you.
Set a days-before-expiry threshold once and let PulseStack carry the reminder for you, on every check, across every channel.
SSL certificate monitoring continuously checks your website's TLS/SSL certificates for expiry dates, chain validity, protocol versions, and configuration errors. PulseStack™ connects to your server from outside your network and inspects the certificate exactly as a browser would. If anything is wrong, you get alerted before visitors see a warning.
Certificate authorities issue certificates with a limited validity period to ensure regular key rotation and security updates. Most certificates from Let’s Encrypt last 90 days, while commercial CAs issue 1-year certificates. Starting in 2026, major CAs are moving to 200-day maximum lifespans. When a certificate expires, browsers block access to your site with a full-screen security warning. Over 35% of users immediately abandon sites showing these warnings.
PulseStack detects expired certificates, certificates approaching expiry, broken or incomplete certificate chains, missing intermediate certificates, deprecated TLS protocols (TLS 1.0 and 1.1), weak cipher suites, hostname mismatches where the certificate does not cover the domain being served, and revoked certificates. Each check validates the full connection exactly as browsers do.
PulseStack sends escalating alerts as your certificate approaches expiry. The first alert goes out at 30 days, giving your team plenty of time to plan. Follow-up alerts fire at 14 days, 7 days, and 1 day remaining. You can configure which team members receive which alert levels and through which channels. Late-stage alerts can trigger voice calls and PagerDuty incidents for maximum urgency.
Yes. PulseStack monitors wildcard certificates (*.example.com), multi-domain SAN certificates, and single-domain certificates. It validates that the Subject Alternative Names listed on the certificate match the domains you are serving. If you add a new subdomain that is not covered by your wildcard or SAN certificate, the hostname mismatch is flagged immediately.
A certificate chain is the trust hierarchy connecting your domain certificate to a root Certificate Authority that browsers recognise. The chain typically includes your leaf certificate, one or more intermediate certificates, and the root CA. If any link is missing or expired, browsers reject the entire connection. PulseStack validates every link in the chain on every check.
TLS 1.0 and 1.1 have known vulnerabilities and are disabled by default in all major browsers since 2020. PCI DSS compliance requires TLS 1.2 as a minimum. If your server still accepts connections on deprecated protocols, it is vulnerable to downgrade attacks. PulseStack flags deprecated protocol support so you can disable it before it becomes a compliance issue.
Yes. When your site uses a CDN, PulseStack checks the certificate served by the CDN edge, which is exactly what your visitors see. Different CDN edges can serve different certificates, so multi-location monitoring from 7 global locations is particularly valuable for catching edge-specific certificate issues that only affect certain regions.
Google uses HTTPS as a ranking signal and will deindex pages that return certificate errors. If search engine crawlers encounter an expired certificate during a crawl, your pages can drop out of search results. By monitoring certificates proactively and renewing before expiry, you prevent the SEO damage that comes from even a brief certificate-related outage.
Auto-renewal tools like Certbot and ACME clients fail more often than people expect. Common causes include expired DNS validation tokens, disabled cron jobs, blocked ports, changed server configurations, and rate limits from the certificate authority. PulseStack acts as an external safety net. Even if your internal renewal process reports success, PulseStack verifies what browsers actually see when they connect to your server.
Yes. The SSL certificate checker at the top of this page is completely free with no account required. Enter any domain to instantly see the certificate issuer, validity dates, days remaining, and protocol version. For continuous monitoring with automated alerts, sign up for a free account with 50 monitors included.
Starting in early 2026, major certificate authorities including DigiCert and Sectigo are moving to 200-day maximum lifespans, down from the current 398 days. This means certificates will need renewing roughly twice a year instead of once. For organisations managing dozens or hundreds of domains, automated monitoring becomes essential to keep track of the increased renewal frequency.
Start free with no card, watch your first monitors in minutes, and add certificate insight from the Pro plan whenever you are ready. Annual billing saves 20%, and paid plans include a 14-day trial.