SSL/TLS · DNS · Domain Expiry

Proactive SSL, DNS, and domain monitoring.

A lightweight way to verify SSL/TLS certificates, DNS records, and domain expiry across your fleet. Set up in minutes, programmable via REST API, with 9 alert channels. Optimized for AI-driven infrastructure.

monitored endpointsdemo data14 probes · 5m
api.certack.io
cert valid · 41d left
2m ago
shop.example.com
cert expires in 9 days
2m ago
old.cdn.net
A record missing
2m ago
status.internal
cert valid · 120d left
2m ago
next sweepin 3m 11s

What we monitor

SSL/TLS

Certificate expiry, issuer, subject alternative names, chain validation, signature algorithm, and CT log monitoring for unauthorized issuance.

Per-site thresholds: 60, 30, 14, 7, 1 days, or any custom lead time.

DNS

A, AAAA, CNAME, MX, TXT, and NS record tracking. Detects record changes and DNS hijacking attempts.

Diff-based change detection with full historical record state.

Domain

Registration expiry, registrar, registrant changes, and WHOIS-based monitoring.

Multi-stage expiry warnings at 90, 30, 14, 7, and 1 days before lapse.

Developer API

Programmable monitoring

REST API with Bearer-token authentication. Add sites, trigger on-demand checks, query status, and manage alert channels from your scripts and CI pipelines.

terminal
# Register a site for monitoring
curl -X POST https://api.certack.com/v1/sites \
-H "Authorization: Bearer ct_your_api_key" \
-d '{"domain": "example.com", "check_types": ["ssl", "dns"]}'
# Read SSL/TLS state for any domain
curl https://api.certack.com/v1/public/check-ssl?domain=google.com
{ "valid": true, "days_remaining": 63, "issuer": "Google Trust Services" }

MCP & programmatic access

Supercharged for the AI era

Expose SSL, DNS, and domain status to Claude and other MCP clients. The public endpoint checks any domain without signup; the private endpoint reads your own monitored sites.

claude-code·MCP: Certack
Connected

Start by telling your AI assistant:

Read https://certack.com/SKILL.md and follow the instructions to monitor example.com
Show raw API example
terminal
# Public: check any domain, no API key
curl -X POST https://api.certack.com/v1/public/mcp \
-d '{"jsonrpc": "2.0", "id": 1, "method": "tools/list"}'
# Private: your monitored sites' status
curl -X POST https://api.certack.com/v1/mcp \
-H "Authorization: Bearer ct_your_api_key" \
-d '{"jsonrpc": "2.0", "id": 2, "method": "tools/call", "params": {"name": "list_sites"}}'

Failure modes we detect

Certificate expiry destroys trust signals

Browsers surface "Not Secure" warnings. Visitors abandon sessions. Search engines demote ranking. Recovery requires both renewal and reputation work.

DNS hijacks enable downstream compromise

Undetected record changes route legitimate traffic to attacker-controlled infrastructure. Credentials and session tokens are exposed on your domain.

Public tool

Inspect any domain's certificate chain

No signup required. View issuer, expiry, signature algorithm, and full SAN list before creating an account.

$

Alert channels

Email
Slack
Discord
Microsoft Teams
Telegram
DingTalk
Feishu
PagerDuty
Webhook
Email
Slack
Discord
Microsoft Teams
Telegram
DingTalk
Feishu
PagerDuty
Webhook

Free: in-dashboard alerts. Starter and Pro: Email, Slack, Discord, Microsoft Teams, Telegram, DingTalk, Feishu, PagerDuty, and generic webhooks.

Pricing

Pricing for every operational scale

Every plan includes SSL/TLS, DNS, and domain monitoring. REST API available on all plans. Cancel any time.

Free

For individual projects and evaluation

$0/mo

  • 2 monitored sites
  • In-dashboard alerts
  • REST API access
  • External alert channels
Start Free

Starter

For small teams and production side-projects

$9.9/mo17% OFF

$11.9/momonthly billing

$8.25/mo billed yearly ($99/yr)

  • 10 monitored sites
  • All nine alert channels
  • Email, Slack, Discord, Teams, Telegram, DingTalk, Feishu, PagerDuty, Webhook
  • REST API access
Get Started

Pro

For production workloads and small SRE teams

$15.9/mo17% OFF

$19/momonthly billing

$13.25/mo billed yearly ($159/yr)

  • 20 monitored sites
  • All nine alert channels
  • Email, Slack, Discord, Teams, Telegram, DingTalk, Feishu, PagerDuty, Webhook
  • REST API access
Choose Pro

Need more?

Volume pricing, higher API limits and custom monitoring setups — talk to us and we'll size a plan for you.

Contact sales

Save 17% with annual billing. REST API on every plan.

FAQ

1. Sign up for Certack — start on the free plan, no credit card needed. 2. Add the domain or host you want to monitor. 3. Alerts are pre-configured for 60, 30, 14, 7 and 1 days before expiry — adjust the thresholds per site if you like. 4. Pick your notification channels: email, Slack, Discord, Microsoft Teams, Telegram, DingTalk, Feishu, PagerDuty or a webhook. Done — you will receive an alert whenever any of your certificates is approaching its expiration date.

1. Sign up for Certack. 2. Add the domain you want to watch. 3. Domain registration is checked weekly and you are alerted 60, 30, 14, 7 and 1 days before it expires. 4. Set your notification channels once — they apply to every check. You will be warned well before the domain can lapse.

1. Sign up for Certack. 2. Add the domain or host whose certificate you want to watch. 3. Certificate change monitoring runs automatically — issuer changes, SAN changes and renewals are detected. 4. You get a notification showing exactly what changed: old vs new issuer, expiry date and SANs. Unexpected certificate changes can be an early sign of a security breach, so review every alert you receive.

Use the free SSL Checker on our homepage: type any domain and you instantly see the issuer, validity dates and certificate chain — no signup required. When you also want to be notified before expiry, create a free account and add the domain to monitoring.

Yes. The free plan monitors 2 sites with SSL, DNS and domain monitoring — daily certificate and DNS checks, weekly domain checks, and in-dashboard alerts. No credit card required and it never expires. Upgrade only when you need more sites or external alert channels.

Free: 2 sites. Starter: 10 sites. Pro: 20 sites. Every plan includes all three monitoring types (SSL, DNS, domain) and REST API access. If you need more than 20 sites, contact us.

Any SSL/TLS certificate on any public host, from any certificate authority — shared hosting, CDNs, load balancers, appliances. You can also monitor domain registration (expiry, registrar, WHOIS changes) and DNS records (A, AAAA, CNAME, MX, TXT, NS). Nothing to install and no DNS changes required.

Everything that matters for certificate health: issuer, expiry date, subject and SAN entries, signature algorithm, and the full certificate chain. Certack also watches Certificate Transparency logs and alerts you if a new certificate is issued for your domain that you did not request.

Yes. Wildcard, multi-domain and IP-SAN certificates are fully supported. All SAN entries are shown in your dashboard and on SSL checks, and any change to the SAN list triggers a certificate-change alert.

Certificate Transparency logs record every SSL/TLS certificate issued for your domain — including ones you did not request. Certack continuously scans these logs, keeps a fingerprint baseline per site, and alerts you the moment an unexpected certificate appears. An unrequested certificate is a common early sign of a man-in-the-middle setup or a phishing campaign using your brand.

The failure is recorded with the exact error (connection refused, handshake failure, invalid certificate, timeout), the dashboard surfaces it under the site, and your configured alert thresholds fire on the channels you have enabled. You can also re-run a single site at any time from the dashboard or the API.

Yes. Certack monitors the certificate actually served at the public endpoint your visitors see — for Cloudflare-fronted sites that is the edge certificate. If you also want to watch the origin certificate itself, add the origin hostname as a separate site.

Yes. Certack ships a native MCP (Model Context Protocol) server, so any MCP-compatible assistant can manage your monitoring directly: list and add monitored sites, run SSL, DNS and domain checks on demand, pull alert lists and certificate change history, and resolve alerts — authenticated with your ct_ API key. The same surface is also available as a REST API with an OpenAPI 3.1 spec at /openapi.yaml, on every plan.

Start monitoring in 30 seconds

No credit card required. Two sites free for the lifetime of the account.