Certificate expiry alert schedule

One email at 7 days is how certificates quietly expire over a long weekend.

What Let’s Encrypt used to send

Until 4 June 2025, Let’s Encrypt emailed the ACME account contact when a certificate was 20 days from expiry, and again closer in. That mail was about the issued cert, not necessarily the one on the balancer, and it stopped. The replacement is “run your own monitor.”

What a single 7-day mail gets wrong

Vendors that send one notice a week out assume the on-call will see it, have access, and can ship a renew the same day. In practice:

Red Sift Certificates Lite (and similar “one email at ~7 days” products) are better than nothing. They are not a schedule. They are a single shot.

30 / 7 / 1

SSLert uses four levels, for both the TLS certificate and the domain registration:

Each level is sent at most once per 24 hours per domain and channel. That is enough to catch a missed first mail without becoming noise. Free plan checks daily; Pro checks every 15 minutes, so the 1-day and expiry notices are not waiting on a 24-hour tick.

SSLert dashboard showing days remaining so 30/7/1 alerts have something to fire on
Days remaining on the wire — the schedule is useless without this number.

The schedule only helps if you are looking at the live handshake. A CT-only or CA-inbox-only tool can still be wrong while 30/7/1 fires on a stale file. Check the hostname at sslert.com/check.

See days remaining on a host