← all metrics

SSL Certificate Expiry

Grande and above

Why it matters

An SSL certificate is what makes the padlock appear in the browser bar and what makes your domain serve over HTTPS. When it expires, browsers show a security warning to every visitor. Traffic drops immediately.

A certificate expiry is not a gradual degradation. It is a hard cutoff. At the moment of expiry, every modern browser displays a full-screen warning to anyone trying to reach your site. Most visitors stop there. Search engines continue crawling, but a site forced back to HTTP after certificate expiry faces a trust signal problem.

Auto-renewal systems usually prevent expiry, but they fail. The failure modes include: the domain email address associated with the certificate being inaccessible, a DNS change breaking the verification challenge, a billing problem with the certificate authority or hosting provider, or a multi-domain certificate that was not extended to include a new subdomain.

How we check it

We open an SSL connection to your domain and read the certificate expiry date directly. This checks the actual certificate in use, not any configuration file or hosting panel setting. If the certificate being served differs from what your panel shows, we catch the discrepancy.

We notify you when the expiry date crosses 30 days out, then 15, then 5, then 1 day. Each threshold triggers one notification. If the certificate is renewed, the threshold resets and notifications begin again from the appropriate level.

What to watch for

A 30-day warning is comfortable. A 5-day warning means auto-renewal has failed and you need to act now. At 1 day, renew manually and verify the new certificate is propagating correctly across your CDN or hosting infrastructure.

Domain expiry can block certificate renewal — if the domain lapses, the verification challenge fails. Check both together.