Domain expiry vs SSL expiry

Two different clocks. Both can take a site offline. Mixing them up wastes a weekend.

SSL / TLS certificate

Issued by a certificate authority (often Let’s Encrypt). Usually lasts 90 days or up to a year. When it expires, HTTPS breaks even if DNS still points at your server. Fix: renew or re-issue the cert.

Domain registration

Paid to a registrar (the right to use example.com). Often one year at a time. When it expires, DNS can disappear after grace/redemption periods — email and the site go dark. Fix: renew at the registrar, not in Certbot.

What Expiry Watch shows

The free checker looks up the live certificate (port 443 unless you specify another) and, when the registry publishes it, the domain registration expiration. Some names have no public registration date; we omit that rather than guess.

Daily email alerts today watch SSL days-left (30 / 14 / 7 / 1). Domain dates appear on the instant check so you can renew at the registrar before auto-renew fails.

Run the free SSL + domain check · Watch SSL on up to 3 hosts free

Related: Why SSL expiry monitoring matters · Monitor SSL for clients

Terms of use — use at your own risk.