SSL & domain expiry
How SutramX checks SSL certificates on every HTTP check, shows certificate and domain registration details, and reminds you before either expires.
Every website and API monitor watches the site's TLS certificate in two ways. Each regular check validates the certificate as part of the request, so an expired or invalid certificate fails the check right away. Separately, the Domain & SSL card tracks when the certificate and the domain registration expire, and can email you (and your chat channels) before they do.
There is no separate SSL monitor type: add a website or API monitor for an https:// URL and the SSL tracking comes with it.
Certificate errors on every check#
With Fail if the HTTPS certificate is invalid or expired turned on (the default), each check fails if the certificate is invalid. The check history shows one of these error classes:
| Error class id | Message |
|---|---|
ssl_expired | TLS certificate has expired |
ssl_hostname_mismatch | TLS certificate hostname does not match the requested host |
ssl_self_signed | TLS certificate is self-signed |
ssl_revoked | TLS certificate has been revoked |
ssl_untrusted_chain | TLS certificate chain is incomplete or not issued by a trusted authority |
ssl_not_yet_valid | TLS certificate is not valid yet |
These open incidents and send alerts like any other failure. To stop one of them from notifying you, untick it under Alert on these HTTP errors in the monitor editor.
If your site intentionally uses a self-signed or private certificate, untick Fail if the HTTPS certificate is invalid or expired in the monitor's advanced options. The check then accepts the certificate, and the Domain & SSL card still reports the problem so you stay informed.
See HTTP & keyword monitors for every other HTTP setting.
The Domain & SSL card#
Open a website or API monitor's detail page to see the Domain & SSL card.
| Row | What it shows |
|---|---|
| Certificate valid until | The certificate's expiry date with the days left, or how long ago it expired |
| Issuer | The certificate authority that issued it |
| Certificate problem | Shown in red when the certificate chain doesn't validate or the host name doesn't match, with the reason |
| Domain expires | The domain registration's expiry date and days left, or Unavailable |
| Registrar | The domain's registrar |
The certificate date turns amber when fewer than 30 days are left and red when fewer than 7 are left or the certificate is invalid. The domain date uses the same colours.
How the details are collected.
- The certificate is read with a TLS connection to the monitor's host and port (443 unless the URL says otherwise). Plain
http://URLs have no certificate to check. - The certificate chain is validated against the standard trusted root store and checked against the host name. The issuer and dates are shown even when validation fails.
- Domain expiry and registrar come from the public registration data service (RDAP). SutramX tries the full host name, then its parent domains, for example
app.shop.example.com,shop.example.com, thenexample.com. If the registry doesn't publish an expiry date, the card shows Unavailable; SutramX never guesses a date.
When the details update. The card shows when they were last checked ("Checked 2 hours ago"). Click Refresh (or Check now the first time) for a live lookup. While expiry reminders are on, SutramX also refreshes the details automatically every 6 hours. Live refreshes are limited to 20 per 15 minutes per user.
Expiry reminders#
Expiry reminders are off by default and are set per monitor.
- Open the monitor's detail page.
- On the Domain & SSL card, tick Expiry email. The setting is saved straight away.
- Optionally change the days ahead value (1–90) and click Save. The default is 30 days.
- To receive the reminders by email, also turn on SSL Certificate Expiry under Alerts → On-call & escalation in the sidebar (this email preference is off by default). The card links to it.
Only the workspace owner can change a monitor's reminder settings.
| Setting | What it does | Default / limits |
|---|---|---|
| Expiry email | Turns reminders on for both the certificate and the domain | Off |
| days ahead | When reminders start | 30 days (1–90) |
Reminder schedule#
Reminders are sent separately for the certificate and for the domain. Each milestone is sent once per expiry date; after you renew, the schedule starts again for the new date.
- Days aheadIf more than 15
- 15 daysbefore
- 7 daysbefore
- 2 daysbefore
- 24 hoursbefore
- ExpiryRenew!
- +1, 2, 3 daysif not renewed
| Milestone | Sent when |
|---|---|
| N days before expiry | Expiry first comes within your days ahead value (only when it is more than 15 days) |
| 15 days before expiry | Expiry is 15 days away or less |
| 7 days before expiry | Expiry is 7 days away or less |
| 2 days before expiry | Expiry is 2 days away or less |
| 24 hours before expiry | Expiry is 1 day away or less |
| 1, 2 and 3 days after expiry | The certificate or domain has expired and is still not renewed |
Milestones earlier than your days ahead value are skipped. For example, with days ahead set to 10, the first reminder arrives when expiry is 10 days away, followed by the 7-day, 2-day and 24-hour reminders.
Reminders only run while the monitor is active, so pausing a monitor also pauses its reminders.
Where reminders go#
- Email: to the monitor's alert recipients, when the SSL Certificate Expiry preference is on. See Email & push.
- Chat apps and webhooks: connected channels such as Slack, Microsoft Teams, Discord and Telegram, and webhooks, receive the reminder whenever the monitor's reminders are on, whatever the email preference. Webhooks receive the events
ssl.expiringanddomain.expiring. See Slack, Teams & chat apps and Webhooks.
A reminder includes the monitor, URL, expiry date and which milestone it is, for example SSL certificate for Marketing site expires in 7 days.
Webhook payload#
A webhook receives a flat JSON body like this:
{
"event": "ssl.expiring",
"title": "SSL certificate for Marketing site expires in 7 days",
"url": "https://app.sutramx.com/dashboard/3f1c9a52-7d1e-4c3b-9a55-1f0b6f2d8e41",
"monitor_id": "3f1c9a52-7d1e-4c3b-9a55-1f0b6f2d8e41",
"monitor_name": "Marketing site",
"monitor_url": "https://example.com",
"kind": "ssl",
"expires_at": "2027-03-04T23:59:59.000Z",
"days_remaining": 7,
"stage": "pre_7d"
}event is ssl.expiring or domain.expiring, and kind is ssl or domain. url links to the monitor in the dashboard. stage is one of pre_<N>d (your early notice), pre_15d, pre_7d, pre_2d, pre_24h, post_1d, post_2d or post_3d.
Configure reminders through the API#
curl -X PUT "https://api.sutramx.com/monitors/MONITOR_ID/domain-ssl-notifications" \
-H "Authorization: Bearer sk_your_api_key" \
-H "Content-Type: application/json" \
-d '{ "enabled": true, "threshold_days": 21 }'threshold_days must be a whole number from 1 to 90. To read the current details use GET https://api.sutramx.com/monitors/MONITOR_ID/domain-ssl, and to run a live lookup use POST https://api.sutramx.com/monitors/MONITOR_ID/domain-ssl/refresh.
Common questions#
Do I need one monitor per certificate? Each website or API monitor tracks the certificate of its own host. To watch several hosts, add a monitor for each.
The domain expiry shows "Unavailable". Some registries, including many country-code domains, don't publish an expiry date through RDAP. The certificate is still tracked.
I renewed my certificate but the card shows the old date. The card shows the last lookup. Click Refresh.
I turned on reminders but got no email. Check that SSL Certificate Expiry is on under Alerts → On-call & escalation, that the monitor has alert recipients, and that expiry is within your days ahead value.
Does a certificate problem make my monitor go down? Only if Fail if the HTTPS certificate is invalid or expired is on, which it is by default. Expiry reminders are separate and never change the monitor's status.
Related
Last updated . Something unclear or missing on this page? Tell us at support@sutramx.com.