SSL monitoringNew: domain expiry

Renew before
anyone notices.

SSL certificate and domain expiry monitoring on every HTTPS monitor. Reminders up to 90 days ahead, and silence once you’ve renewed.

On every plan, Free included. 20 monitors free, no credit card required.

Trusted by teams that put uptime first.

Read customer stories

Six ways a certificate breaks. Hyperping checks for every one.

  • cert · example.com · 7 days leftreminder · Slack and email

    The renewal job that quietly stopped

    Automated renewals fail without a sound: an expired API token, a DNS change, a full disk. Pick when the first alert goes out, from 90 days to a day before expiry, with reminders after it.

    Expiry alerts
  • curl: unable to get local issuer certificateincomplete chain

    Fine in Chrome, broken everywhere else

    A server that doesn’t send its intermediates still works in most browsers, which repair the chain. curl, Android and API clients don’t. Hyperping verifies the chain the way they do.

    Chain validation
  • cert · revoked by its issueralert · SSL channels

    Revoked, and still being served

    After a key leak or a mis-issuance, the authority revokes the certificate. Hyperping checks the stapled response, the OCSP responder and the revocation list, which is what Let’s Encrypt now relies on.

    Revocation checks
  • cert · *.example.net ≠ shop.example.comhostname mismatch

    The right certificate on the wrong host

    A new subdomain behind the wrong load balancer, a CDN serving someone else’s certificate. Every name the certificate covers is matched against the host, wildcards included, the way browsers match them.

    Hostname checks
  • tls 1.1 only · sha-1 intermediateoutdated TLS

    The legacy server everyone forgot

    Current browsers refuse servers that only speak TLS 1.0 or 1.1. Hyperping flags them, along with SHA-1 or MD5 signatures and keys shorter than 2048-bit RSA.

    TLS and crypto checks
  • domain · example.io · 12 days leftreminder · once per domain

    The domain nobody renewed

    When a registration lapses, the website, email and certificates go down together, and anyone can buy the name. Hyperping reads the expiry date from the registry and reminds you ahead of time.

    Domain expiry monitoring

Every check a browser makes. Once a day, on every HTTPS monitor.

Each check opens a TLS connection the way a browser would and verifies what the server actually serves. A certificate your provider renewed but your server doesn’t serve yet still counts as expiring.

  • Expired

    Alerts

    The certificate, or an intermediate the server relies on, is past its end date.

  • Not yet valid

    Alerts

    The start date is in the future, often a server clock problem or a certificate installed too early.

  • Hostname mismatch

    Alerts

    None of the names in the certificate covers the monitored host. Wildcards and IP addresses are matched like browsers do.

  • Self-signed

    Alerts

    The certificate signs itself instead of being issued by an authority.

  • Untrusted root

    Alerts

    The chain ends at an authority browsers don’t trust, such as a private or internal CA.

  • Incomplete chain

    Alerts

    The server doesn’t send its intermediate certificates. Some browsers repair this; curl, Android and most API clients don’t.

  • Invalid chain

    Alerts

    Any other reason the chain doesn’t verify against the public trust store.

  • Revoked

    Alerts

    The authority revoked the certificate. Checked with the stapled response, the OCSP responder or the revocation list (CRL).

  • Outdated TLS

    Alerts

    The server only offers TLS 1.0 or 1.1, which current browsers refuse.

  • Weak signature

    Alerts

    The certificate or an intermediate is signed with SHA-1 or MD5.

  • Weak key

    Shown on the monitor

    A key shorter than 2048-bit RSA or 224-bit ECDSA.

Checked on every HTTPS monitor, and on port monitors whose port speaks TLS directly: 443, 8443, 993, 995, 465, 636, 8883 and more. A URL like https://example.com:8443 is checked on its own port.

Reminded until it’s renewed. Then not once more.

Choose the first alert per monitor. Reminders follow at 30, 15, 7, 3 and 1 days below it, and stop the moment the new certificate is served.

  1. First alert1 · 3 · 7 · 15 · 30 · 60 · 90 days

    Pick how many days before expiry the first alert goes out, per monitor, in its Notifications tab. Or never.

  2. Reminders30 · 15 · 7 · 3 · 1 days

    With reminders on, one follows at each step below the threshold. If a check couldn’t run the day a reminder was due, it goes out on the next one, once.

  3. On-calllast 24 hours · PagerDuty, Opsgenie

    Email and chat channels get every reminder. PagerDuty and Opsgenie are only paged in the final day, and the renewal resolves the page.

  4. Renewedre-read before sending · reminders stop

    The certificate is read again right before each reminder. Renewed in the meantime, nothing goes out. Already warned, you get a renewed notice instead.

The channels you pick.On-call only when it’s urgent.

Certificate errors and reminders go to the monitor’s SSL channels and to your team by email. PagerDuty and Opsgenie are paged in the last 24 hours only.

  • Slack
  • Microsoft Teams
  • Google Chat
  • PagerDuty
  • Opsgenie
  • Discord
  • Telegram
  • Email
  • Webhooks

The domain behind the certificate. Watched too, straight from the registry.

When a registration lapses, the website, email and certificates stop at once, and an expired domain can be bought by someone else. Domain expiry alerts warn you first.

  1. 1

    Read from the registry

    The registered domain behind each monitor, api.status.example.co.uk checked as example.co.uk, for HTTP, ping, port and DNS monitors. Daily inside 45 days, weekly before that.

  2. 2

    One reminder per domain

    Ten monitors on the same domain in a project send one reminder, not ten, at the earliest threshold among them: 7, 14, 30, 60 or 90 days before the registration ends.

  3. 3

    Late renewals noticed

    Registrars often renew in the last days, so the registry is asked again right before each reminder. Renewed meanwhile, nothing goes out, and any PagerDuty or Opsgenie page is resolved.

Domain registration · example.comRegistered
Domain
example.com
Expires
Mar 14, 2027 · 164 days left
Registrar
Example Registrar, LLC
Source
RDAP
Status
client transfer prohibited
Monitors on this domain
6 · one reminder
Alert
30 days before

Read from the registry over RDAP, the successor of WHOIS. Six monitors point at example.com, so its reminders go out once, at the earliest threshold among them.

Certificates as code. API, Terraform, MCP and webhooks.

  1. 1

    Set it per monitor

    ssl_alert_days, ssl_reminders, ssl_notify_on_change and domain_alert_days, in the API, the Terraform provider and the MCP server, so every new monitor ships with the right thresholds.

  2. 2

    Hear about every change

    Turn on certificate change notifications to see each renewal, new issuer or new key, with the new and the previous certificate side by side. A CDN rotating several certificates doesn’t trigger it.

  3. 3

    Wire it into your tools

    Webhooks get certificate errors in the same shape as downtime alerts. Notices carry their own event and isDown: false, so a consumer acting on down ignores them.

PUT /v1/monitors/:uuidbash
curl -X PUT https://api.hyperping.io/v1/monitors/mon_123abc \
  -H "Authorization: Bearer $API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "ssl_alert_days": 30,
    "ssl_reminders": true,
    "ssl_notify_on_change": true,
    "domain_alert_days": 30
  }'

What teams say about Hyperping.

Guillermo Rauch
CEO, Vercel
@hyperping is really amazing
Fabrice Gregoire
Site Reliability Engineer, Alma
Hyperping’s reputation in our company is that it’s more reactive than Datadog. We usually get notifications from Hyperping before Datadog.
Pierre Renaudin
CTO, Slite
We picked Hyperping to bring a high quality incidents and status reporting dashboard to our users.
Moritz Dausinger
CEO & Founder, Refiner
We have the real-time alerts from Hyperping telling us if the app is down. These are sometimes arriving even before AWS notices or notifies us.
Gary Gaspar
CEO & Founder, Marker.io
We couldn’t imagine running our SaaS business without Hyperping now.
Jakob Bo Storjohann
CEO, Ideanote
Hyperping nails all aspects: from smooth setup to peace of mind and attentive customer service.

You learn your site is down from a customer’s support ticket.

Uptime, status pages and on-call.One platform. Know before your customers do.

Uptime monitoring

Catch downtime the moment it happens, from multiple regions, before your customers notice.

Server monitoring

A lightweight agent tracks CPU, memory and disk, so you spot trouble before it turns into downtime.

Browser checks / E2E

Playwright tests that catch broken sign-ins and checkouts before your customers do.

Cron job monitoring

Get alerted when a backup or scheduled job silently fails to run, not days later.

api.acme.com is down. HTTP 503 from Paris, confirmed from Frankfurt and N. Virginia.9:42 AM
Incident published on status.acme.com. 1,240 subscribers notified by email.9:43 AM
api.acme.com is back up. Downtime 4 min 12 s, incident resolved automatically.9:46 AM
View incident

Notification channels

Alerts reach the right person on Slack, Teams, SMS or a phone call, whichever wakes them up.

SSL monitoring

Keep certificates in check. Get alerted before they expire, so your customers always connect securely.

On-call calendar

Plan rotations, share the load, and see who’s on call. Every incident reaches the right person, at the right time.

Three tools. One better bill.Monitoring, status pages, and on-call. Together.

USD · Monthly billing for every plan

The tool mix

Three subscriptions to keep it all running.

Example stack
  • Pingdom100 uptime + 20 advanced checks
    $149/mo
  • StatuspagePublic Startup + private Growth
    $348/mo
  • PagerDutyProfessional · 10 users × $25
    $250/mo
Combined cost

$747/month

$8,964 over 12 months

Everything connected, from the first check.

Business
  • 1,000 monitors
  • 10 status pages
  • 20 team members
  • On-call & escalations
  • 20-second checks
  • Priority support
One platform. One subscription.

$299/month

$3,588 over 12 months
60% less

Save $5,376 a year with this mix.

Explore pricing
Pricing sources & assumptions

Reviewed . All amounts are USD; local currency prices may differ.

  • Pingdom Synthetic Monitoring: $149/month for 100 uptime checks, 20 advanced checks and 350 SMS credits. USD rate from our August 17, 2026 review; the live calculator served EUR during this check, so the USD rate was not independently reverified today.
  • Statuspage: one public Startup page ($99/month, 1,000 subscribers, 10 team members) and one private Growth page ($249/month, 300 authenticated subscribers, 15 team members).
  • PagerDuty Professional: $25/user/month on monthly billing, for 10 users. Its $21 rate requires annual billing.
  • Hyperping Business: $299/month on monthly billing. The advertised $249/month is a rounded annual equivalent of $2,990/year and is not used in this comparison.

This is one example of a three-tool stack, not the cheapest possible setup or a feature-for-feature match. Pingdom and PagerDuty also include status-page features; a separate Statuspage subscription may not be needed by every team. Usage charges and paid connectors are not included. Annual totals are 12 monthly payments, not annual subscription quotes.

Questions about SSL and domain monitoring.

What is SSL certificate monitoring?

SSL monitoring checks the TLS certificate a server actually serves and warns you before it expires or stops being trusted. Hyperping checks the certificate of every HTTPS monitor once a day, with no extra setup: expiry, hostname, chain, trust, revocation, TLS version and signature strength. See SSL monitoring in the docs.

How far ahead does Hyperping warn me before a certificate expires?

You choose per monitor: 1, 3, 7, 15, 30, 60 or 90 days before expiry, or never. With reminders on, another alert follows at each step below that threshold, so 30 days means alerts at 30, 15, 7, 3 and 1 days. If the certificate is renewed in the meantime, the remaining reminders are skipped.

Which SSL certificate errors does Hyperping detect?

Expired and not yet valid certificates, hostname mismatches, self-signed certificates, untrusted roots, incomplete or invalid chains, revoked certificates, servers that only offer TLS 1.0 or 1.1, and SHA-1 or MD5 signatures. Weak keys are shown on the monitor without sending an alert. A new problem alerts the monitor’s SSL channels, and a resolved notification follows once everything is fixed.

Does Hyperping check whether a certificate was revoked?

Yes. It uses the OCSP response the server staples, then the authority’s OCSP responder, then its certificate revocation list (CRL). The CRL step matters for Let’s Encrypt, which stopped running OCSP in 2025.

Can Hyperping monitor domain name expiration?

Yes. Domain expiry alerts read the registration’s expiry date from the registry, over RDAP or WHOIS, and remind you 7 to 90 days before it lapses. Ten monitors on the same domain send one reminder, not ten. Monitors created from the dashboard start at 14 days. Registries that don’t publish dates, such as .de, .eu, .ch, .be and .nl, are skipped. See domain expiry monitoring.

Where do SSL and domain alerts go?

Expiry reminders go to everyone on the project by email and to the monitor’s SSL notification channels: Slack, Microsoft Teams, Discord, Google Chat, Telegram and webhooks. PagerDuty and Opsgenie are only paged in the last 24 hours, and the renewal resolves the page. See integrations.

Is SSL monitoring included in the free plan?

Yes. SSL and domain expiry monitoring are included on every plan, Free included, for every HTTPS monitor you create. The Free plan includes 20 monitors and needs no credit card. See pricing.

Can I configure SSL alerts with the API or Terraform?

Yes. Monitors in the API take ssl_alert_days, ssl_reminders, ssl_notify_on_change and domain_alert_days, and return the days left in ssl_expiration and domain_expiration. The Terraform provider’s hyperping_monitor resource and the MCP server take the same settings.

Your certificates, watched in a minute.