Automated daily certificate checks

SSL Certificate Monitoring

Stop finding out about expired certificates from your users. SSLNudge monitors your SSL/TLS certificates every day and alerts you — long before they expire or break.

  • Free for 10 certificates
  • No credit card
  • No agent to install

What SSLNudge monitors on every certificate

The expiry date is the headline, but most outages come from the things around it.

Expiry & lead-time alerts

A daily read of every certificate’s notAfter date, with warnings at 60 / 30 / 14 / 7 / 1 days so a renewal never lapses.

Chain completeness

Catches a missing intermediate — the kind that works in Chrome but breaks curl, Java and mobile clients.

Hostname / SAN match

Confirms every hostname you serve is covered by the certificate’s Subject Alternative Names.

TLS version & cipher

Flags a server that drops to a deprecated protocol or stops offering TLS 1.3 after a config change.

Issuer & OCSP status

Tracks which CA issued each certificate and surfaces revocation so a valid date isn’t the whole story.

Instant failure alerts

When a check that was passing newly fails, you hear about it immediately — not at the next renewal.

How certificate monitoring works

1

Add your domains

Paste a hostname (and port if it isn’t 443) or import a list. Public sites, APIs, mail servers and custom TLS ports.

2

SSLNudge checks daily

We open a real TLS connection to each host every day and record expiry, chain, hostname, issuer and protocol.

3

You get alerted in time

Warnings reach you over email, Slack and webhooks with real lead time, so you renew on your schedule, not under fire.

Why monitor instead of checking by hand

Manual checks only catch what you remember to look at, when you remember to look.

openssl by hand

Perfect for a one-off investigation, but running a command is not a monitoring strategy — it only checks the moment you remember to run it.

A calendar reminder

Reminders go stale the moment a certificate is reissued early or a new host is added, and they don’t catch a broken chain or a bad renewal.

SSLNudge

Re-checks every certificate daily from outside your network, verifies far more than the date, and escalates through channels you actually watch.

Simple pricing

Start free with 10 certificates. Upgrade for more certs, the API, private certificates and team workspaces.

MonthlyAnnually1 month free

Free

$0USD/mo

Free forever

Generous free tier — monitor 10 certificates at no cost.

  • 10 certificates
  • 1 user
  • Daily checks
  • Slack alerts
  • API access
Get started

Starter

$17USD/mo

per month, billed annually

For a growing set of domains.

  • 20 certificates
  • 1 user
  • Slack alerts
  • Additional email recipients
  • API access
Start free trial

Growth

$35USD/mo

per month, billed annually

For teams that need Microsoft Teams + collaborators.

  • 80 certificates
  • 2 users
  • Microsoft Teams notifications
  • Slack alerts
  • Additional email recipients
  • API access
Start free trial

Complete

$72USD/mo

per month, billed annually

Internal certs, webhooks and everything in Growth.

  • 200 certificates
  • 3 users
  • Private certificate monitoring (agents)
  • Webhooks
  • Microsoft Teams + Slack
  • API access
Start free trial

Scale

$136USD/mo

per month, billed annually

Enterprise-scale certificate monitoring.

  • 500 certificates
  • 5 users
  • Everything in Complete
  • Priority support
Start free trial

Have more than a few hundred certificates or need a custom plan? Get in touch.

SSL certificate monitoring FAQ

What is SSL certificate monitoring?

SSL certificate monitoring is the practice of automatically and repeatedly checking your SSL/TLS certificates so problems are caught before your users hit them. A monitor opens a TLS connection to each host on a schedule, reads the certificate, and alerts you about anything that will break trust — an approaching expiry date, a broken chain, a hostname mismatch, or a weak protocol.

How do I monitor an SSL certificate’s expiration?

Add the hostname to SSLNudge once. It opens a TLS connection to that host every day, reads the certificate’s expiry date, and emails or Slacks you at configurable lead times (60, 30, 14, 7 and 1 days by default) so the renewal never lapses. There is nothing to install and no command to remember to run.

How often should certificates be checked?

At least once a day. Certificates can be renewed, rotated or misconfigured at any time, and with public certificate lifespans shrinking toward 47 days the window for a quiet failure keeps narrowing. A daily external check gives you days of lead time to act.

What does SSLNudge monitor besides the expiry date?

Chain completeness (a missing intermediate fails for many clients), hostname and SAN match, the negotiated TLS version and cipher, the issuing certificate authority, and OCSP/revocation status. Any of these can break a site even when the expiry date is far off.

Can I monitor internal or private certificates?

Yes. Public monitors cannot reach hosts behind a firewall, so internal services, private PKI and mutual-TLS certificates are checked from inside your network and reported to the same dashboard. They expire just like public certificates and are the easiest to forget.

How will I be alerted?

Over email, Slack and generic webhooks, at lead times you choose, plus an instant alert the moment a previously-passing check fails. Routing alerts to more than one channel means a single missed message never becomes a missed renewal.

Is SSL monitoring free?

Yes — the free plan monitors 10 certificates with daily checks and email, Slack and webhook alerts, with no credit card. Paid plans add more certificates, the API, private certificate monitoring and team workspaces.

How is this different from running openssl myself?

openssl s_client is great for a one-off check, but it only runs when you remember to run it and only reports what you think to look at. SSLNudge runs the same inspection automatically every day, from outside your network, across every host, and tells you before something breaks instead of after.

Put your certificates on autopilot

Add your domains once and let SSLNudge watch them every day — and ping you in plenty of time.

Start monitoring free