Skip to content

SSL certificate expiration checks

Create an SSL certificate check, enter a bare public hostname and set positive warning/critical day thresholds. Critical must be less than warning.

Setting Behavior
Name Required
Hostname Bare hostname without a scheme or path
Warning days At or below this remaining-day value: degraded
Critical days At or below this remaining-day value: down
Schedule Fixed hourly lookup
Notification groups Assigned account groups

Warning 30 and critical 7 mean that equality at either boundary is already a breach. An expired certificate is down. Inspect the first recorded expiration date to confirm you are monitoring the intended hostname.

This check watches certificate expiration, not the complete security posture of TLS or every certificate in your infrastructure. A TLS or lookup failure without a usable expiration date does not independently prove expiration; review the latest recorded result and date.

For endpoint availability and TLS connection errors use a separate website check. Pingstack does not issue or renew certificates on your behalf.