SSL/TLS · DNS · Domain Expiry
Proactive SSL, DNS, and domain monitoring.
A lightweight way to verify SSL/TLS certificates, DNS records, and domain expiry across your fleet. Set up in minutes, programmable via REST API, with 9 alert channels. Optimized for AI-driven infrastructure.
What we monitor
Certificate expiry, issuer, subject alternative names, chain validation, signature algorithm, and CT log monitoring for unauthorized issuance.
Per-site thresholds: 60, 30, 14, 7, 1 days, or any custom lead time.
A, AAAA, CNAME, MX, TXT, and NS record tracking. Detects record changes and DNS hijacking attempts.
Diff-based change detection with full historical record state.
Registration expiry, registrar, registrant changes, and WHOIS-based monitoring.
Multi-stage expiry warnings at 90, 30, 14, 7, and 1 days before lapse.
Developer API
Programmable monitoring
REST API with Bearer-token authentication. Add sites, trigger on-demand checks, query status, and manage alert channels from your scripts and CI pipelines.
MCP & programmatic access
Supercharged for the AI era
Expose SSL, DNS, and domain status to Claude and other MCP clients. The public endpoint checks any domain without signup; the private endpoint reads your own monitored sites.
Start by telling your AI assistant:
Read https://certack.com/SKILL.md and follow the instructions to monitor example.comShow raw API example
Failure modes we detect
Certificate expiry destroys trust signals
Browsers surface "Not Secure" warnings. Visitors abandon sessions. Search engines demote ranking. Recovery requires both renewal and reputation work.
DNS hijacks enable downstream compromise
Undetected record changes route legitimate traffic to attacker-controlled infrastructure. Credentials and session tokens are exposed on your domain.
Public tool
Inspect any domain's certificate chain
No signup required. View issuer, expiry, signature algorithm, and full SAN list before creating an account.
Alert channels
Free: in-dashboard alerts. Starter and Pro: Email, Slack, Discord, Microsoft Teams, Telegram, DingTalk, Feishu, PagerDuty, and generic webhooks.
Pricing
Pricing for every operational scale
Every plan includes SSL/TLS, DNS, and domain monitoring. REST API available on all plans. Cancel any time.
Free
For individual projects and evaluation
$0/mo
- 2 monitored sites
- In-dashboard alerts
- REST API access
- External alert channels
Starter
For small teams and production side-projects
$9.9/mo17% OFF
$11.9/momonthly billing
$8.25/mo billed yearly ($99/yr)
- 10 monitored sites
- All nine alert channels
- Email, Slack, Discord, Teams, Telegram, DingTalk, Feishu, PagerDuty, Webhook
- REST API access
Pro
For production workloads and small SRE teams
$15.9/mo17% OFF
$19/momonthly billing
$13.25/mo billed yearly ($159/yr)
- 20 monitored sites
- All nine alert channels
- Email, Slack, Discord, Teams, Telegram, DingTalk, Feishu, PagerDuty, Webhook
- REST API access
Need more?
Volume pricing, higher API limits and custom monitoring setups — talk to us and we'll size a plan for you.
Save 17% with annual billing. REST API on every plan.
FAQ
1. Sign up for Certack — start on the free plan, no credit card needed. 2. Add the domain or host you want to monitor. 3. Alerts are pre-configured for 60, 30, 14, 7 and 1 days before expiry — adjust the thresholds per site if you like. 4. Pick your notification channels: email, Slack, Discord, Microsoft Teams, Telegram, DingTalk, Feishu, PagerDuty or a webhook. Done — you will receive an alert whenever any of your certificates is approaching its expiration date.
1. Sign up for Certack. 2. Add the domain you want to watch. 3. Domain registration is checked weekly and you are alerted 60, 30, 14, 7 and 1 days before it expires. 4. Set your notification channels once — they apply to every check. You will be warned well before the domain can lapse.
1. Sign up for Certack. 2. Add the domain or host whose certificate you want to watch. 3. Certificate change monitoring runs automatically — issuer changes, SAN changes and renewals are detected. 4. You get a notification showing exactly what changed: old vs new issuer, expiry date and SANs. Unexpected certificate changes can be an early sign of a security breach, so review every alert you receive.
Use the free SSL Checker on our homepage: type any domain and you instantly see the issuer, validity dates and certificate chain — no signup required. When you also want to be notified before expiry, create a free account and add the domain to monitoring.
Yes. The free plan monitors 2 sites with SSL, DNS and domain monitoring — daily certificate and DNS checks, weekly domain checks, and in-dashboard alerts. No credit card required and it never expires. Upgrade only when you need more sites or external alert channels.
Free: 2 sites. Starter: 10 sites. Pro: 20 sites. Every plan includes all three monitoring types (SSL, DNS, domain) and REST API access. If you need more than 20 sites, contact us.
Any SSL/TLS certificate on any public host, from any certificate authority — shared hosting, CDNs, load balancers, appliances. You can also monitor domain registration (expiry, registrar, WHOIS changes) and DNS records (A, AAAA, CNAME, MX, TXT, NS). Nothing to install and no DNS changes required.
Everything that matters for certificate health: issuer, expiry date, subject and SAN entries, signature algorithm, and the full certificate chain. Certack also watches Certificate Transparency logs and alerts you if a new certificate is issued for your domain that you did not request.
Yes. Wildcard, multi-domain and IP-SAN certificates are fully supported. All SAN entries are shown in your dashboard and on SSL checks, and any change to the SAN list triggers a certificate-change alert.
Certificate Transparency logs record every SSL/TLS certificate issued for your domain — including ones you did not request. Certack continuously scans these logs, keeps a fingerprint baseline per site, and alerts you the moment an unexpected certificate appears. An unrequested certificate is a common early sign of a man-in-the-middle setup or a phishing campaign using your brand.
The failure is recorded with the exact error (connection refused, handshake failure, invalid certificate, timeout), the dashboard surfaces it under the site, and your configured alert thresholds fire on the channels you have enabled. You can also re-run a single site at any time from the dashboard or the API.
Yes. Certack monitors the certificate actually served at the public endpoint your visitors see — for Cloudflare-fronted sites that is the edge certificate. If you also want to watch the origin certificate itself, add the origin hostname as a separate site.
Yes. Certack ships a native MCP (Model Context Protocol) server, so any MCP-compatible assistant can manage your monitoring directly: list and add monitored sites, run SSL, DNS and domain checks on demand, pull alert lists and certificate change history, and resolve alerts — authenticated with your ct_ API key. The same surface is also available as a REST API with an OpenAPI 3.1 spec at /openapi.yaml, on every plan.
Learn
Monitoring guides
Practical how-tos for checking expiry, watching DNS, and never losing a domain.
How to Check SSL Certificate Expiration
Browser, OpenSSL, curl, and free online checker — four ways to read any certificate's expiry in seconds.
How to Monitor SSL Certificate Expiration
Check frequency, 60/30/14/7/1-day alert thresholds, chain validation, and CT logs.
How to Check DNS Records
Read any zone with dig, nslookup, or an online lookup — and tell propagation from real errors.
Start monitoring in 30 seconds
No credit card required. Two sites free for the lifetime of the account.