Certificates and domains expire on a schedule you cannot see

Expiry warnings at 30, 14, 7 and 1 days out, invalid-chain detection with SNI, and the same treatment for domain registration and DNS resolution.

Automated renewal is not the same as renewal

Everyone has certificate automation now, which is exactly why certificate outages are still common: the renewal is invisible until the day it silently stops working. The ACME account got rate-limited. The HTTP-01 challenge path is now behind auth. The cron job doing the renewal is the cron job nobody noticed had stopped. In every case the certificate keeps working — right up to the hour it does not, and then every browser and every API client refuses at once.

A TLS check reads what a visitor's browser would read, from outside your network:

The domain underneath it

A perfectly valid certificate on a domain whose registration lapsed is still an outage, and it is the one nobody has a dashboard for — the renewal notice went to an inbox belonging to someone who left.

Confirmed before it pages you

Like every other check type, a failure has to be confirmed from a second independent EU probe region before anyone is alerted. A resolver failure in one region is a resolver failure, not an outage.

What it does not do

It does not renew anything, and it does not hold your keys or your registrar credentials. It watches from the outside and tells you early. That is deliberate: a monitor with the power to change your certificates is a much larger thing to trust than one that only reads.

Where it runs from

Two EU probe regions, data in France on Scaleway, with a DPA available before you ask. Security & data →