SSL monitoring for agencies

Uptime tools tell you the site is down. They do not tell you the certificate dies on Tuesday.

The job is a portfolio, not a ping

An agency or freelancer with 20–50 client hostnames already has Pingdom, Better Stack, or a host panel. Those products ask “did HTTP 200 come back?” A certificate can be 48 hours from expiry while every ping is green. The failure mode is a browser interstitial on Monday morning, not a timeout.

What you need is a list of hostnames, a live handshake on each, and a 30 / 7 / 1-day alert to a channel the on-call actually reads — email, Slack, Telegram, ntfy, or a webhook into the ticket system.

What not to do

A working shape

SSLert dashboard listing hostnames with days remaining until TLS expiry
One list of hostnames, live handshake, days remaining. Not an uptime grid.

Keep one watch list per practice, not per client login. Add the public names you terminate or that you are contracted to keep alive (apex, www, app, mail if you run it). Alert into the same Slack the pager uses. When a 30-day warning fires, file the renew against the client; when 7 days fires, treat it as yours.

SSLert Free is 10 domains, email only, daily checks. Pro is $15/month or $150/year for 50 domains and every channel. There is no Team plan on the site — do not plan around one. Self-hosted is AGPL if 50 is not enough and you will run SQLite yourself.

Paste a client hostname into sslert.com/check before you add it. If the handshake is already wrong, watching it will only confirm that.

Check a client hostname