How an agency keeps a client domain and certificate inventory

Corrections: support@domainvane.com

The list is the job

An agency does not forget "SSL" in the abstract. It loses a specific name: the campaign host that was added on a Friday, the www that was reissued without the apex, the domain the client registered on a personal credit card. The inventory is the list of those names, plus enough context that the right person can renew the right object.

Shorter public certificates make the list less forgiving. The CA/Browser Forum caps subscriber certificates at 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. Let's Encrypt ended its expiration emails on 4 June 2025 and has published a shorter issuance schedule inside that cap. A yearly spreadsheet tab matched yearly certificates. It matches poorly when names renew several times a year on machines the account manager does not log into.

This is a process. None of the steps below requires a particular product. The last section says what Domainvane will and will not take off the list.

What a row needs

One row per hostname, not one row per client. Treat example.com and www.example.com as separate monitored hostnames; they may be covered by the same SAN certificate or may terminate on different certificates. Track the name that is in the browser bar.

ColumnWhy it is there
HostnameThe exact name to check on port 443.
ClientWho would notice if the site broke, in your words.
Certificate expirynotAfter from a live handshake, with the day you read it.
IssuerLet's Encrypt, a commercial CA, or a host's bundled certificate.
Who renews the certificateAgency automation, the client, or the host. "Unknown" is an acceptable value. It is better than a blank that looks finished.
Registration expiryThe date from the registrar or from RDAP, labeled registry or registrar.
Who receives registrar mailThe contact ICANN's renewal notices go to. Often not the agency.
Where it is hostedSo a chain or expiry failure has a machine attached.

Leave registration expiry blank, or write "unknown," when you cannot read it. Country-code TLDs and some gTLD lookups do not return a clean RDAP date. Inventing a date from a PDF proposal will train the team to trust the sheet over the registrar.

ICANN's Expired Registration Recovery Policy sends renewal notices to the registrant email in the registration data: about a month before, about a week before, and again shortly after expiry if the name is still not renewed. If that inbox is the client's, the agency will not see the notice. The inventory row is how you remember that the notice is going somewhere else.

Why the spreadsheet goes stale

The sheet fails in ordinary ways. Someone exports it for a sales deck and the deck becomes the copy people edit. A hostname gets added in the hosting panel during a launch and never returns to the sheet. A date is typed once, at onboarding, and an ACME client has reissued the certificate twice since. The person who understood the columns leaves.

A spreadsheet has no handshake. It cannot notice that the server is sending cert.pem rather than fullchain.pem, and it cannot notice that the registry auto-renewed the name while the client's card was declined. The sheet is a snapshot from the day someone paid attention.

Use the sheet as the place you decide which names you are responsible for. Use a check against the live service for when they expire. The moment both jobs live only in the sheet, the sheet is already late.

From the sheet to a monitor

Move names in batches, not as a heroic Saturday.

  1. Filter to names the agency is actually on the hook for. A hostname the client insisted on renewing themselves can stay on the sheet with "client renews" in the column. Put it on the monitor too if you will still get the phone call when it breaks. Skip it if the contract says you will not.
  2. Normalize the names. Lowercase, no https://, no path, no bare IP addresses. Internationalized names should be entered as the Unicode name or the punycode, consistently, so you do not add both.
  3. Paste. A useful importer tells you, per line, whether the name was added, was already on the account, was invalid, or hit the plan cap. Read that report. A paste that "succeeds" with a single toast is how duplicates and typos hide.
  4. Treat paused names as still occupying a seat. Pausing is how you stop checks without losing the row. It is not how you free room for a new client.
  5. Wait for the first real result. Pending means the check has not run. Unknown on the domain column means RDAP did not provide a date. Both are information. Fill the sheet from the results, not the other way around.
  6. Assign an owner who checks the dashboard alert state. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested). Do not assume every provider will place alerts in the primary inbox.

Plan size is a business fact, not a technical one. Three hostnames is enough to test the path on the accounts that scare you. A book of client sites needs a cap that can hold the book, including the paused rows you are not ready to delete.

Domainvane's paste accepts newlines, commas, and spaces, and returns added, duplicate, invalid, or limit per entry. Paused hostnames count toward the cap. The checks behind a saved name are port 443 for the certificate and RDAP for the registration. There is no public API in this version, so the paste in the account is the import. The public bulk page explains that. It does not fan out to a list of hosts anonymously.

Handing the list to a client

Clients ask for proof, usually at renewal, or when they are leaving, or when their own IT team wants to see that you are watching.

Give them the hostname list, the latest status for each name (certificate days remaining, and the registration date or the word unknown), and a way to look again without your password. Keep the account login, the webhook URLs, and the rest of the client book.

A read-only link is the third item. Domainvane's client report pages are included on Agency and Agency+. The Agency limit is 50 pages and Agency+ is 200. Each page has a label and an explicit list of hostnames. The URL is https://domainvane.com/r/<token>. The token is long and random, but it is a bearer link rather than authentication: anyone with it can view that list. Revoking the page makes the URL a 404, the same response as a token you never issued.

The page is on Domainvane's host. It does not wear the agency's domain, and it does not carry the agency's logo. If the contract requires a branded status page on the agency's domain, this version does not meet that clause. Say so in the handover note rather than implying the token page is white-label. Send the link as a secret. It is not a login, and it is not a document you can "unsend" after someone forwards it, except by revoking.

When the client leaves, delete their hostnames, or pause them if the contract has a tail. Deleting the whole account removes every client and cannot be undone from the product. Local backups can retain rows until they age out. Offboard one client by deleting that client's hostnames.

A first week

Fill the columns for ten hostnames from live checks. Paste those ten into a monitor and compare. Where the sheet and the handshake disagree, keep the handshake. Decide who reviews dashboard alert state, then add the next batch. A colleague should be able to say whether you monitor a hostname, what the last check saw, and who renews it.

Start with the hostnames you are afraid of losing. Domainvane's free plan covers three of them and shows their current status and alert state on the dashboard. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested).

Sources

Checked 2026-09-25.

  • CA/Browser Forum, Baseline Requirements version 2.3.0 (7 September 2026), section 1.2.2: subscriber certificate maximum validity 200 days from 15 March 2026, 100 days from 15 March 2027, 47 days from 15 March 2029. https://github.com/cabforum/servercert/blob/BRs/v2.3.0/docs/BR.md
  • Let's Encrypt, "Decreasing Certificate Lifetimes to 45 Days," 2 December 2025 (shorter issuance schedule; recommendation to monitor renewals). https://letsencrypt.org/2025/12/02/from-90-to-45
  • Let's Encrypt, "Expiration Notification Service Has Ended," 26 June 2025 (service ended 4 June 2025). https://letsencrypt.org/2025/06/26/expiration-notification-service-has-ended
  • ICANN, registrant explainer for the Expired Registration Recovery Policy (renewal notices go to the registrant email on the name). https://www.icann.org/resources/pages/registrant-about-errp-2018-12-07-en
  • ICANN, registrar advisory on registry versus registrar expiration dates, 30 September 2025. https://itp.cdn.icann.org/en/files/contracted-parties-communications/registrar-registration-expiration-date-30-09-2025-en.pdf