Skip to content
SSL Certificate Monitoring

Never let an SSL certificate expire again

Automatic monitoring of TLS certificates across every domain you manage. Get escalating expiry alerts at 30, 14, 7, and 1 day out — so you fix renewals before browsers show your visitors a security warning.

330+ edge locations
Multi-channel alerts
1 minute checks
1 asset downCheck asset status below

Total Assets

8

Monitored

Protected

6

All checks passing

Down

1

Failing checks

Reviewing

1

Active scan

Avg Uptime

99.97%

Last 30 days

Avg Latency

146ms

Fleet average

A

Security Score

96/100
2 Medium
What's affecting your score2 findings
PassingMedium

Assets

upsec.watch

https://upsec.watch

99.99%

Protected

api.upsec.watch

https://api.upsec.watch

99.97%

Protected

billing-worker

worker:billing-prod

99.94%

Reviewing

404.upsec.watch

https://404.upsec.watch

—

Down

Recent Events

404.upsec.watch12:44 UTC

404.upsec.watch is down (timeout)

api.upsec.watch12:38 UTC

api.upsec.watch recovered

cdn-proxy-0312:22 UTC

cdn-proxy-03 added to monitoring

upsec.watch12:15 UTC

Security scan completed — A grade

billing-worker11:58 UTC

2 medium findings detected

404.upsec.watch11:30 UTC

404.upsec.watch recovered

Domain Discovery

Scanning for subdomains…

Monitoring 7,634 user assets across 330+ edge locations
3 regions1 min cadence365d retention

Escalating expiry alerts

Receive notifications at 30, 14, 7, and 1 day before certificate expiry. Alerts escalate in urgency as the deadline approaches — catch renewal failures early, avoid emergency fixes on expiry day.

Full chain validation

Every check validates the complete trust chain from leaf certificate through intermediates to the root CA. Detect missing intermediates, incorrect ordering, and revoked certificates before they trigger browser warnings.

Protocol version monitoring

Identify which TLS versions your servers negotiate and flag deprecated protocols like TLS 1.0 and 1.1. Stay ahead of browser deprecation timelines and compliance requirements with actionable version reports.

Full chain verification

Every link in the trust chain, validated

Most tools only check if the leaf certificate is valid. UpSec.Watch validates the complete chain — from your server certificate through every intermediate to the trusted root CA. Missing intermediates and incorrect chain ordering cause mobile browser failures that desktop testing never catches.

  • Root → Intermediate → Leaf validation on every check cycle
  • Detect missing intermediates that break mobile Safari and Android browsers
  • Track certificate issuer changes — a potential indicator of compromise
cert-chain
Root CA
DigiCert Global Root G2
Intermediate
DigiCert SHA2 Extended Validation
Leaf Certificate
*.example.com
Valid
Escalating alerts

Four warnings before the red screen

Automated renewal fails more often than you think — DNS misconfigurations, rate limits, expired account keys, stale certbot configs. UpSec.Watch sends escalating alerts at 30, 14, 7, and 1 day before expiry, each more urgent than the last. No more emergency certificate renewals at 2 AM.

  • Escalating urgency — from gentle reminder to critical alert
  • Catch failed auto-renewals before they impact visitors
  • Multi-channel delivery — email, Slack, Discord, Telegram, webhook
expiry-alerts
30dFirst notice
14dReminder
7dUrgent
1dCritical
Protocol security

Know exactly what your server negotiates

TLS 1.0 and 1.1 are deprecated by all major browsers. HSTS headers prevent protocol downgrade attacks. UpSec.Watch checks both — showing you which TLS versions your server offers and whether your security headers are correctly configured. Clear pass/fail results, no cryptography degree required.

  • Flag deprecated TLS 1.0/1.1 still enabled on your servers
  • Verify HSTS headers prevent protocol downgrade attacks
  • Monitor TLS 1.3 adoption across your entire domain portfolio
tls-protocols
TLS 1.3
Active
TLS 1.2
Active
TLS 1.1
Deprecated
TLS 1.0
Deprecated
HSTS Header
Strict-Transport-Security: max-age=31536000

Comprehensive SSL certificate monitoring

Certificate expiry countdown

Track exact days remaining until certificate expiration for every domain. Dashboard shows a clear countdown with color-coded urgency so expiring certificates never get lost in the noise.

Certificate chain validation

Validates the full trust chain on every scan — leaf, intermediate, and root certificates. Catches missing intermediates and chain ordering issues that cause mobile browser trust failures.

TLS version detection

Identifies supported TLS protocol versions on your server. Flags deprecated TLS 1.0/1.1 configurations and confirms TLS 1.3 availability for modern security compliance.

HSTS header check

Verifies HTTP Strict Transport Security headers are present and correctly configured. Detects missing HSTS, short max-age values, and absent includeSubDomains directives.

Mixed content detection

Identifies pages loading insecure HTTP resources over HTTPS connections. Mixed content triggers browser warnings and degrades the padlock indicator your visitors rely on.

Auto-renewal verification

Monitors certificate issue and expiry dates over time to verify automated renewal is working. Get alerted if an ACME renewal fails silently — before the old certificate actually expires.

Multi-domain support

Monitor SSL certificates across hundreds of domains from a single dashboard. SAN (Subject Alternative Name) certificates are fully parsed so every covered domain is tracked individually.

Wildcard certificate tracking

Supports wildcard certificates (*.example.com) with clear visibility into which subdomains are covered. Tracks wildcard renewal separately from individual domain certificates.

Set up SSL monitoring in three steps

01

Add your domain

Enter any HTTPS URL or domain name. UpSec.Watch connects to your server, retrieves the certificate, and begins monitoring immediately — no agent installation or DNS changes required.

02

We scan your certificates

UpSec.Watch checks your TLS certificate chain, protocol versions, and expiry dates on every monitoring cycle. Results appear in your dashboard within seconds of adding the domain.

03

Get alerted before expiry

Receive escalating alerts via email, Slack, Discord, or any configured channel as certificates approach expiration. Recovery notifications confirm when renewals complete successfully.

330+

Edge locations

30d

Early warning

99.9%

Platform uptime

6

Alert channels

Frequently asked questions

UpSec.Watch sends escalating alerts at 30, 14, 7, and 1 day before your SSL certificate expires. Each alert includes the exact expiry date, the certificate issuer, and a direct link to the affected asset — giving you plenty of time to renew manually or verify that auto-renewal completed successfully.

Yes. Every scan validates the complete certificate chain from your server's leaf certificate through any intermediates to the trusted root CA. We detect missing intermediates, incorrect chain order, self-signed certificates in production, and revoked certificates — all of which can cause browser trust warnings even when the leaf certificate itself is valid.

UpSec.Watch detects the TLS protocol versions your server supports, including TLS 1.2 and TLS 1.3. We flag servers still offering deprecated protocols like TLS 1.0 or 1.1, which are no longer considered secure and have been disabled by all major browsers. You get clear guidance on which protocols to disable.

Even with Let's Encrypt or other ACME-based auto-renewal, certificates can fail to renew due to DNS misconfigurations, rate limits, expired account keys, or certbot errors. UpSec.Watch acts as your safety net — if auto-renewal succeeds, you see a healthy certificate with a fresh expiry date. If it fails, you get alerted well before the browser warning hits your visitors.

SSL certificate monitoring is included in all UpSec.Watch plans, including the free Hobby tier. Every HTTPS asset you add is automatically checked for certificate health, chain validity, and expiry dates. Paid plans add multi-region SSL validation so you can catch geo-specific certificate issues across CDN edge nodes.