CertiMonitor

Nothing on your domains expires without warning.

CertiMonitor watches your TLS certificates, domain registrations and email records, and tells your team before any of them lapse.

Next 12 months at FernhillSample data
  • api.fernhill.io certificate expires in 6 days
  • fernhill.io registration expires in 23 days
  • shop.fernhill.io certificate expires in 41 days
  • vpn.fernhill.internal uploaded certificate expires in 74 days
  • mail.fernhill.io certificate expires in 118 days
  • status.fernhill.io certificate expires in 203 days
  • fernhill.co.uk registration expires in 287 days
  • www.fernhill.io certificate expires in 352 days

What it watches

Add a domain and CertiMonitor checks it on a schedule from then on. Each check reads the same records your visitors' browsers and mail servers do.

TLS certificates

Checked from the outside, the way browsers see them: when it expires, whether the chain is trusted, and whether it covers the hostname.

api.fernhill.io:443
issuer
Let's Encrypt R11
expires
in 6 days
chain
trusted, hostname matches

Domain registration

Expiry, registrar and status straight from the registry over RDAP, so a lapsed renewal or a domain in redemption never catches you out.

fernhill.io
registrar
Gandi SAS
expires
in 23 days
status
client transfer prohibited

Email authentication

SPF, DKIM and DMARC on your sending domains, so a DNS change doesn't quietly send your mail to spam.

_dmarc.fernhill.io
dmarc
v=DMARC1; p=reject
spf
v=spf1 include:_spf.google.com -all
dkim
google._domainkey found

Why teams switch to it

Three expiry dates, one place
Certificates, domain registrations and email records share one timeline and one set of alerts, instead of a registrar reminder, a CA email and a calendar entry.
Alerts you won't learn to ignore
A warning at 30 days and a critical at 7 by default, one message when a problem starts and one when it's fixed. Change the thresholds for any domain.
The right people, the right channel
Send each rule to its own channels: critical alerts to Slack with @here, the rest to email. Tags keep a long domain list sorted.
Checked as often as you need
Daily on the free plan, down to hourly on paid plans, and Check now for the moment you've just renewed.
Certificates we can't reach
Internal CAs, VPN and client certificates: paste the PEM and track its expiry alongside the rest. Private keys are rejected, never stored.
Careful with your access
Two-factor and passkeys for every account, alert destinations encrypted at rest, and signed webhooks your endpoint can verify.

Alerts where your team already is

Email, Slack, Discord, Microsoft Teams, or a webhook into anything else. Here's the same alert in each.

C

CertiMonitorvia Slack webhook

@here Critical TLS certificate expires in 6 days

api.fernhill.io

Renew the certificate, or check why auto-renewal hasn't replaced it yet.

Certificate expires
Oct 5, 2026
Issuer
Let's Encrypt R11
View in CertiMonitor

Add your first domain in a minute.

Create an account, enter a hostname, and the first check runs straight away.