Check any domain's certificate — expiry, issuer, and covered names. Free, no account needed.
Looks up certificate transparency logs via crt.sh — no connection to your server required.
An expired SSL certificate takes your service offline for every user — browsers show a hard "connection not secure" error with no bypass for ordinary visitors. Unlike many infrastructure failures, a certificate expiry is a hard deadline that announces itself weeks in advance and then hits exactly on schedule.
The window between "will expire soon" and "has expired" is collapsing. In 2026, Apple, Google, and Mozilla are moving toward 47-day maximum certificate lifetimes. When certs expire every six weeks instead of every year, manual renewal processes break down — teams that monitored an annual renewal calendar will find themselves fighting fires every month.
The fix is automation backed by governance: auto-renew, but with an audit trail showing who authorized each certificate, what policy it was issued under, and when it was deployed.
Days remaining under 30
Renewal should already be in progress. For manually managed certs, this is urgent. For auto-renewing certs, verify the renewal system is working.
Validity period over 90 days
Older certificates with 1- or 2-year validity were issued before the industry moved toward shorter lifetimes. These will not be reissuable at the same duration when they expire.
Issuer: self-signed or unknown CA
A self-signed cert or one from an unrecognized CA will show trust errors in browsers and most HTTP clients. For internal services, use a properly distributed internal CA.
SANs not covering all your hostnames
If your service is reachable at multiple hostnames (with and without www, API subdomain, etc.), all of them must appear as Subject Alternative Names in the certificate.
CertForge monitors all your certificates and alerts your team before they expire — with the governance trail your auditors need.
Start monitoring freeUp to 10 certificates free. No credit card.