- Bitmovin
- HBO Nordic
- Obsidian
- Laravel
- Fathom Analytics
- PHP 8
- Stanford University
- Takeaway.com
- IGN
- VRT NWS
- spatie
After automation runs
The job finished. Did the right certificate reach production?
Oh Dear connects from outside every 30 minutes and evaluates the certificate your server actually presents, not the file a provider says it issued. When a renewal changes the served certificate, a before-and-after comparison shows exactly what changed.
Previously served
Now served
A server move can change more than the certificate. See DNS changes too with DNS monitoring.
The whole presented chain
It worked in the browser, but not in the app.
Browsers and applications differ in what they have cached and what they trust. A valid leaf can look fine in a familiar browser check while a missing or unhealthy intermediate breaks another client.
Chain validation
Validate every certificate the server presents.
Oh Dear evaluates the leaf and the intermediate certificates the monitored endpoint returns. It reports the served chain; it does not discover every certificate your organisation owns.
- Leaf certificate shop.example Served
- Intermediate CA Example Intermediate CA Linked
- Trust result Chain builds to a trusted root Healthy
I just entered my domain and Oh Dear took care of the rest. I was pleasantly surprised to see changes in my SSL cert chain and mixed content reports.
Paul Redmond, Contributor at Laravel News
Oh Dear reports what it observes. Renewal, deployment and repair stay with your existing automation or provider.
Not just an expiry date
Know which certificate problem you are looking at.
Each check answers a specific operational question about the certificate and chain the monitored server presents.
Expiry and identity
Trust chain
Change history
Operational ownership
Route each alert to the person who owns the fix.
See every monitored site's certificate state in one view, and send each site's alerts only to the person responsible, on the channels your team already uses, without paging everyone for every renewal.
No feature tiers
Every check.
Every plan.
Certificate health is included with Oh Dear's website-health checks on every plan. Choose by the number of sites you monitor, not by which checks you need.
Start with everything on.
Try certificate monitoring alongside uptime, DNS, domain and the rest of the website-health toolkit.
- Certificate health on every plan
- Every monitoring feature included
- Plans scale by monitored site count
- No credit card required
10-day free trial. No credit card.
Before the first check
Questions about SSL certificate monitoring.
What Oh Dear observes, how often it checks, and where certificate monitoring ends.
What is SSL/TLS certificate monitoring?
SSL/TLS certificate monitoring repeatedly checks the certificate and chain a monitored server presents. Oh Dear reports failures involving expiry, validity, hostname coverage, chain health and certificate changes. "SSL" and "TLS" describe the same HTTPS certificate-monitoring category here.
How often does Oh Dear check certificates?
Every 30 minutes, on each monitored site.
How early will Oh Dear warn me before expiry?
By default, 7 days ahead for a Let's Encrypt certificate and 14 days ahead for any other issuer, matching the renewal window each one expects. You can raise that threshold per site, up to 100 days, if your renewal process needs more time.
Does Oh Dear validate the full certificate chain?
Yes. Oh Dear validates every certificate the monitored server presents, including the intermediates. It reports the chain that endpoint serves, so it will not discover certificates the endpoint never presents.
What happens when a certificate changes?
Oh Dear shows a before-and-after comparison of the certificate fields and covered domains it observed. Treat a change as a result to verify: it is usually a renewal, but it can also be a server move or something you did not authorise.
Does Oh Dear renew certificates automatically?
No. Oh Dear monitors the certificate from outside and alerts your team. Issuance, renewal and deployment stay with your existing automation or provider.
Does Oh Dear keep certificate history?
Yes. Detected certificates and past certificate check runs stay available, so you can inspect what the endpoint served previously.
Why monitor SSL certificates?
Because an expired certificate is a full outage: browsers block the page behind a security warning. Renewals fail silently more often than teams expect, whether automation breaks, DNS validation changes, or a wildcard gets missed.
Can I track all my SSL certificates in one place?
Yes. Every monitored site's certificate, including its issuer, expiry date, and chain, appears in one dashboard with per-site alerts. One overview replaces the renewal spreadsheet.
Is there a free SSL certificate monitor?
Oh Dear's 10-day trial monitors your certificates free. One-off checker tools can grade a certificate today, but what they can't do is alert you the week before it expires.
Is certificate monitoring included in every plan?
Yes. Certificate health is included with every plan. Your plan changes with the number of sites you monitor, not with which checks you switch on.
Get started
Start monitoring the certificates your sites actually serve.
Add a site in under a minute. Every feature on. No credit card.