Nothing on your domains expires without warning.
CertiMonitor watches your TLS certificates, domain registrations and email records, and tells your team before any of them lapse.
- api.fernhill.io certificate expires in 6 days
- fernhill.io registration expires in 23 days
- shop.fernhill.io certificate expires in 41 days
- vpn.fernhill.internal uploaded certificate expires in 74 days
- mail.fernhill.io certificate expires in 118 days
- status.fernhill.io certificate expires in 203 days
- fernhill.co.uk registration expires in 287 days
- www.fernhill.io certificate expires in 352 days
What it watches
Add a domain and CertiMonitor checks it on a schedule from then on. Each check reads the same records your visitors' browsers and mail servers do.
TLS certificates
Checked from the outside, the way browsers see them: when it expires, whether the chain is trusted, and whether it covers the hostname.
- api.fernhill.io:443
- issuer
- Let's Encrypt R11
- expires
- in 6 days
- chain
- trusted, hostname matches
Domain registration
Expiry, registrar and status straight from the registry over RDAP, so a lapsed renewal or a domain in redemption never catches you out.
- fernhill.io
- registrar
- Gandi SAS
- expires
- in 23 days
- status
- client transfer prohibited
Email authentication
SPF, DKIM and DMARC on your sending domains, so a DNS change doesn't quietly send your mail to spam.
- _dmarc.fernhill.io
- dmarc
- v=DMARC1; p=reject
- spf
- v=spf1 include:_spf.google.com -all
- dkim
- google._domainkey found
Why teams switch to it
- Three expiry dates, one place
- Certificates, domain registrations and email records share one timeline and one set of alerts, instead of a registrar reminder, a CA email and a calendar entry.
- Alerts you won't learn to ignore
- A warning at 30 days and a critical at 7 by default, one message when a problem starts and one when it's fixed. Change the thresholds for any domain.
- The right people, the right channel
- Send each rule to its own channels: critical alerts to Slack with @here, the rest to email. Tags keep a long domain list sorted.
- Checked as often as you need
- Daily on the free plan, down to hourly on paid plans, and Check now for the moment you've just renewed.
- Certificates we can't reach
- Internal CAs, VPN and client certificates: paste the PEM and track its expiry alongside the rest. Private keys are rejected, never stored.
- Careful with your access
- Two-factor and passkeys for every account, alert destinations encrypted at rest, and signed webhooks your endpoint can verify.
Alerts where your team already is
Email, Slack, Discord, Microsoft Teams, or a webhook into anything else. Here's the same alert in each.
CertiMonitorvia Slack webhook
@here Critical TLS certificate expires in 6 days
api.fernhill.ioRenew the certificate, or check why auto-renewal hasn't replaced it yet.
- Certificate expires
- Oct 5, 2026
- Issuer
- Let's Encrypt R11
Add your first domain in a minute.
Create an account, enter a hostname, and the first check runs straight away.