Never let a certificate expire unexpectedly

SSL/TLS Certificate Monitoring

Expired certificates break trust and break connections. upti.my monitors your SSL/TLS certificates across all domains, alerting you well before expiration and catching chain issues before they affect users.

Certificate expiry: predictable yet catastrophic

SSL certificates have a known expiration date, yet expired certs cause major outages regularly. Auto-renewal helps but isn't foolproof. Rate limits, DNS issues, and configuration drift all cause failures. When a cert expires, browsers show scary warnings and APIs reject connections.

Expiry Alerts

Configurable warnings, 30 days ahead by default.

Chain Validation

Verify complete certificate chains.

TLS Reporting

See the negotiated TLS version and cipher suite.

Hostname Matching

Verify certs match your domains.

Why certificates still expire unexpectedly

Even with automation, certificate issues slip through:

  • Auto-renewal silently fails when certbot crashes with no notification
  • Forgotten domains where old subdomains expire without warning
  • Chain issues with intermediate certs missing, causing mobile to fail
  • Wildcard sprawl where one cert on 20 services multiplies risk

Comprehensive certificate monitoring

upti.my tracks every certificate across your infrastructure. We alert on upcoming expirations, validate chains and hostnames on every real TLS handshake, and give you a single dashboard for all your SSL/TLS health.

  • Configurable expiry alerts, 30 days ahead by default
  • Certificate chain validation
  • Hostname matching verification
  • Negotiated TLS version and cipher suite reported on every check

Getting Started

Set up SSL monitoring in the dashboard:

  1. 1

    Create an SSL Monitor

    Select SSL/TLS as your monitor type and enter your domain.

  2. 2

    Configure Expiry Alerts

    Choose when to get notified. The default is 30 days before expiration — set any threshold that fits your renewal process.

  3. 3

    Let Chain Validation Run

    Every check verifies your full certificate chain and hostname. Catch missing intermediates before they break mobile apps.

  4. 4

    Review Your TLS Details

    Each check reports the negotiated TLS version and cipher suite, so outdated configurations stand out at a glance.

Frequently Asked Questions

upti.my warns you 30 days before expiration by default, and the threshold is fully configurable — set whatever fits your renewal process. This gives you time to renew manually or debug automation issues before users ever see a browser warning.

Every check performs a real TLS handshake and validates the full certificate chain, hostname match, and validity dates — the issues that cause browser warnings and connection failures. You also get upcoming-expiry warnings well before the deadline.

Every check reports the negotiated TLS version and cipher suite, days until expiry, and the certificate's subject and issuer. You always know exactly what your users' browsers are negotiating, and outdated TLS configurations stand out at a glance.

Even with auto-renewal, things fail. Certbot crashes, DNS validation fails, rate limits hit. SSL monitoring catches when auto-renewal doesn't work, giving you time to fix it before expiration.

Related Topics

Run reliability as one connected workflow

Detect failures early, route alerts clearly, coordinate incidents, and keep status updates in sync from one system.