Monitors

SSL & domain expiry

How SutramX checks SSL certificates on every HTTP check, shows certificate and domain registration details, and reminds you before either expires.

Every website and API monitor watches the site's TLS certificate in two ways. Each regular check validates the certificate as part of the request, so an expired or invalid certificate fails the check right away. Separately, the Domain & SSL card tracks when the certificate and the domain registration expire, and can email you (and your chat channels) before they do.

There is no separate SSL monitor type: add a website or API monitor for an https:// URL and the SSL tracking comes with it.

Certificate errors on every check#

With Fail if the HTTPS certificate is invalid or expired turned on (the default), each check fails if the certificate is invalid. The check history shows one of these error classes:

Error class idMessage
ssl_expiredTLS certificate has expired
ssl_hostname_mismatchTLS certificate hostname does not match the requested host
ssl_self_signedTLS certificate is self-signed
ssl_revokedTLS certificate has been revoked
ssl_untrusted_chainTLS certificate chain is incomplete or not issued by a trusted authority
ssl_not_yet_validTLS certificate is not valid yet

These open incidents and send alerts like any other failure. To stop one of them from notifying you, untick it under Alert on these HTTP errors in the monitor editor.

If your site intentionally uses a self-signed or private certificate, untick Fail if the HTTPS certificate is invalid or expired in the monitor's advanced options. The check then accepts the certificate, and the Domain & SSL card still reports the problem so you stay informed.

See HTTP & keyword monitors for every other HTTP setting.

The Domain & SSL card#

Open a website or API monitor's detail page to see the Domain & SSL card.

RowWhat it shows
Certificate valid untilThe certificate's expiry date with the days left, or how long ago it expired
IssuerThe certificate authority that issued it
Certificate problemShown in red when the certificate chain doesn't validate or the host name doesn't match, with the reason
Domain expiresThe domain registration's expiry date and days left, or Unavailable
RegistrarThe domain's registrar

The certificate date turns amber when fewer than 30 days are left and red when fewer than 7 are left or the certificate is invalid. The domain date uses the same colours.

How the details are collected.

  • The certificate is read with a TLS connection to the monitor's host and port (443 unless the URL says otherwise). Plain http:// URLs have no certificate to check.
  • The certificate chain is validated against the standard trusted root store and checked against the host name. The issuer and dates are shown even when validation fails.
  • Domain expiry and registrar come from the public registration data service (RDAP). SutramX tries the full host name, then its parent domains, for example app.shop.example.com, shop.example.com, then example.com. If the registry doesn't publish an expiry date, the card shows Unavailable; SutramX never guesses a date.

When the details update. The card shows when they were last checked ("Checked 2 hours ago"). Click Refresh (or Check now the first time) for a live lookup. While expiry reminders are on, SutramX also refreshes the details automatically every 6 hours. Live refreshes are limited to 20 per 15 minutes per user.

Expiry reminders#

Expiry reminders are off by default and are set per monitor.

  1. Open the monitor's detail page.
  2. On the Domain & SSL card, tick Expiry email. The setting is saved straight away.
  3. Optionally change the days ahead value (1–90) and click Save. The default is 30 days.
  4. To receive the reminders by email, also turn on SSL Certificate Expiry under Alerts → On-call & escalation in the sidebar (this email preference is off by default). The card links to it.

Only the workspace owner can change a monitor's reminder settings.

SettingWhat it doesDefault / limits
Expiry emailTurns reminders on for both the certificate and the domainOff
days aheadWhen reminders start30 days (1–90)

Reminder schedule#

Reminders are sent separately for the certificate and for the domain. Each milestone is sent once per expiry date; after you renew, the schedule starts again for the new date.

Expiry reminders, before it's too late
Certificate and domain reminders arrive at each milestone once per expiry date. Renewing starts the schedule again for the new date.
MilestoneSent when
N days before expiryExpiry first comes within your days ahead value (only when it is more than 15 days)
15 days before expiryExpiry is 15 days away or less
7 days before expiryExpiry is 7 days away or less
2 days before expiryExpiry is 2 days away or less
24 hours before expiryExpiry is 1 day away or less
1, 2 and 3 days after expiryThe certificate or domain has expired and is still not renewed

Milestones earlier than your days ahead value are skipped. For example, with days ahead set to 10, the first reminder arrives when expiry is 10 days away, followed by the 7-day, 2-day and 24-hour reminders.

Reminders only run while the monitor is active, so pausing a monitor also pauses its reminders.

Where reminders go#

  • Email: to the monitor's alert recipients, when the SSL Certificate Expiry preference is on. See Email & push.
  • Chat apps and webhooks: connected channels such as Slack, Microsoft Teams, Discord and Telegram, and webhooks, receive the reminder whenever the monitor's reminders are on, whatever the email preference. Webhooks receive the events ssl.expiring and domain.expiring. See Slack, Teams & chat apps and Webhooks.

A reminder includes the monitor, URL, expiry date and which milestone it is, for example SSL certificate for Marketing site expires in 7 days.

Webhook payload#

A webhook receives a flat JSON body like this:

json
{
  "event": "ssl.expiring",
  "title": "SSL certificate for Marketing site expires in 7 days",
  "url": "https://app.sutramx.com/dashboard/3f1c9a52-7d1e-4c3b-9a55-1f0b6f2d8e41",
  "monitor_id": "3f1c9a52-7d1e-4c3b-9a55-1f0b6f2d8e41",
  "monitor_name": "Marketing site",
  "monitor_url": "https://example.com",
  "kind": "ssl",
  "expires_at": "2027-03-04T23:59:59.000Z",
  "days_remaining": 7,
  "stage": "pre_7d"
}

event is ssl.expiring or domain.expiring, and kind is ssl or domain. url links to the monitor in the dashboard. stage is one of pre_<N>d (your early notice), pre_15d, pre_7d, pre_2d, pre_24h, post_1d, post_2d or post_3d.

Configure reminders through the API#

bash
curl -X PUT "https://api.sutramx.com/monitors/MONITOR_ID/domain-ssl-notifications" \
  -H "Authorization: Bearer sk_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{ "enabled": true, "threshold_days": 21 }'

threshold_days must be a whole number from 1 to 90. To read the current details use GET https://api.sutramx.com/monitors/MONITOR_ID/domain-ssl, and to run a live lookup use POST https://api.sutramx.com/monitors/MONITOR_ID/domain-ssl/refresh.

Common questions#

Do I need one monitor per certificate? Each website or API monitor tracks the certificate of its own host. To watch several hosts, add a monitor for each.

The domain expiry shows "Unavailable". Some registries, including many country-code domains, don't publish an expiry date through RDAP. The certificate is still tracked.

I renewed my certificate but the card shows the old date. The card shows the last lookup. Click Refresh.

I turned on reminders but got no email. Check that SSL Certificate Expiry is on under Alerts → On-call & escalation, that the monitor has alert recipients, and that expiry is within your days ahead value.

Does a certificate problem make my monitor go down? Only if Fail if the HTTPS certificate is invalid or expired is on, which it is by default. Expiry reminders are separate and never change the monitor's status.

Last updated . Something unclear or missing on this page? Tell us at support@sutramx.com.