Expiry warnings at 30, 14, 7 and 1 days out, invalid-chain detection with SNI, and the same treatment for domain registration and DNS resolution.
Everyone has certificate automation now, which is exactly why certificate outages are still common: the renewal is invisible until the day it silently stops working. The ACME account got rate-limited. The HTTP-01 challenge path is now behind auth. The cron job doing the renewal is the cron job nobody noticed had stopped. In every case the certificate keeps working — right up to the hour it does not, and then every browser and every API client refuses at once.
A TLS check reads what a visitor's browser would read, from outside your network:
A perfectly valid certificate on a domain whose registration lapsed is still an outage, and it is the one nobody has a dashboard for — the renewal notice went to an inbox belonging to someone who left.
Like every other check type, a failure has to be confirmed from a second independent EU probe region before anyone is alerted. A resolver failure in one region is a resolver failure, not an outage.
It does not renew anything, and it does not hold your keys or your registrar credentials. It watches from the outside and tells you early. That is deliberate: a monitor with the power to change your certificates is a much larger thing to trust than one that only reads.
Two EU probe regions, data in France on Scaleway, with a DPA available before you ask. Security & data →