Certificate expiry monitoring

Never learn about an expired certificate from a customer.

An expired certificate takes a service down as effectively as any attack: customers see a browser warning, sales stop, and the fix becomes an emergency. The usual cause isn't neglect; it's automatic renewal that failed without telling anyone. Attack Surface Scan checks the certificate each of your systems actually presents and warns you well before the deadline, not after.

No card required to start. Plans from $25/month, flat; first report in minutes.

Why certificates still take sites down

Automation fails silently

A permission changes, a renewal job stops running, and nothing complains until customers' browsers do. The certificate a system actually presents is the only honest signal.

Coverage is wider than the spreadsheet

The main website is tracked; the customer portal, the old marketing site and the subdomain a vendor set up are not. The certificate that expires is always the one nobody wrote down.

Issuance you didn't order

A certificate issued for your name by a provider you don't use is either a misconfiguration or someone preparing to impersonate you. Either way, you want to know the day it happens.

The domain itself can lapse

A domain registration that expires is worse than any certificate problem. The registration deserves the same watch.

What changes with Attack Surface Scan

Warnings that escalate

Reminders from 30 days out (you can change the first threshold), then at 14, 7, 3 and 1 days, with certificates re-checked daily on Starter and four times a day on Growth and above. A separate stalled-renewal alert fires weeks earlier, when a certificate that should have renewed by now hasn't.

Every system, including the found ones

Systems discovered under your domains join monitoring on their own and get certificate checks too, so coverage tracks your real estate instead of a list from last year.

Unapproved certificates caught within the quarter hour

Every publicly trusted certificate is recorded in public logs. Attack Surface Scan reads them every 15 minutes, and a certificate for your name from a provider you haven't approved alerts at once and waits in a review queue.

Alerts that reach the right person

Email, Slack, Microsoft Teams, PagerDuty, Jira or a webhook, the moment a certificate crosses a threshold. The full guide to monitoring expiry →

What you can show

The outage that didn't happen

The change history records each warning and when the renewed certificate appeared: the evidence for a post-incident review, or for the incident that never had to happen.

Renewal status in one attachment

Every dated report shows which systems have certificates expiring or misconfigured, so the state of the whole estate goes to your manager, client or auditor as one PDF.

The technical detail (what is checked on each certificate, extra ports, mail servers, per-domain settings) is in the certificates documentation.

Common questions

How is this better than a calendar reminder or a renewal script?

A reminder tracks the date you wrote down; Attack Surface Scan checks the certificate actually being presented, on every system it has found, and alerts on drift, including certificates renewed but never put in place, and systems you forgot existed. The check is the ground truth, not the plan.

Does it catch certificates on subdomains I haven't listed?

Yes. The public certificate logs are read every 15 minutes, and discovered subdomains are added to monitoring automatically, up to your plan's limit, where they get the same certificate checks. A new subdomain usually surfaces within the quarter hour of its first certificate.

How does this compare with Cert Spotter?

Closely on the certificate side: both watch the public certificate logs, keep an approved provider list, queue unknown certificates, discover subdomains, and check the certificate each system presents. Cert Spotter checks more often on its upper tiers and from more locations; Attack Surface Scan adds everything around the certificate. The full comparison lists where each is ahead.

What about wildcard certificates?

Attack Surface Scan checks what each system actually presents, so a wildcard certificate in place on some systems but not others shows up as exactly that: per-system results rather than an assumption that the wildcard covers everything.

Put every certificate on watch.

Verify your domain and see the state of every certificate in minutes.

Start your 7-day trial

No card required to start. Cancel any time.