Domain expiry vs SSL certificate expiry

"The site's expired" can mean two very different things. Either the TLS certificate (still commonly called the SSL certificate) has passed its end date, or the domain registration has. They have separate dates, are renewed by separate companies, and break a site in different ways. If you manage more than a handful of sites, it helps to track them as two separate items.

Two different things with two different dates

TLS (SSL) certificateDomain registration
What it isA file the web server presents to prove it is the real site and to set up encryptionYour right to use the name, recorded by the registry for that domain ending
Who issues or renews itA certificate authority, often through your host, CDN, or an ACME client like CertbotYour registrar, on behalf of the registry
Where the date livesThe certificate's not-after field, read from the server on port 443The registration record, available through RDAP (and historically WHOIS)
Typical lifetimeMonths or less, and getting shorterUsually one year or more per renewal
How it renewsA new certificate replaces the old oneThe existing registration is extended

When the certificate expires

The domain is still registered and still points at your server. DNS works, the server answers, but the certificate the server presents is past its not-after date.

Browsers show a full-page warning saying the connection isn't private, and most visitors leave. API clients, payment integrations, and apps that connect to the site usually refuse the connection outright. Email is normally unaffected unless the mail server uses the same expired certificate.

The fix is usually quick once someone notices: issue or install a new certificate, or repair the automation that should have done it. The hard part is noticing before your visitors do.

You can see a certificate's expiry for any hostname with the SSL certificate checker. For a fuller walkthrough of reading the result, see how to check when an SSL certificate expires.

When the domain registration expires

Here the certificate may still be perfectly in date. The problem is upstream: the registration for the name has lapsed.

What happens next depends on the registry and the registrar. Commonly the registrar changes the domain's DNS, so the site and often email stop working or point somewhere else. There is usually a period during which the original owner can still renew, sometimes followed by a more expensive recovery period, and eventually the name can be released for anyone to register. The exact stages, timings, and fees vary by domain ending and registrar, so check your registrar's terms rather than relying on a general rule.

A lapsed registration is usually more serious than an expired certificate. It can take email down with the website, and if the name is released, getting it back may not be possible.

Why one date doesn't tell you the other

It is common to assume that if one is fine, the other is too. They aren't linked.

  • A certificate can be valid for months while the registration expires next week.
  • A registration can be paid for years ahead while the certificate expires tomorrow because an automated renewal broke.
  • Auto-renew on both sides fails quietly: an expired card on the registrar account, a DNS change that breaks certificate validation, a site moved to a new host without moving the renewal job.

A certificate checker reads the certificate the server presents. It tells you nothing about the registration. A registration lookup tells you nothing about the certificate. You need both.

Where the domain expiry date comes from, and when it is unknown

The registration expiry date comes from the registry or registrar. Today the standard way to get it is RDAP (Registration Data Access Protocol), a structured replacement for WHOIS.

RDAP doesn't always return a clean answer. Some domain endings don't publish an expiry date through RDAP, some responses are incomplete, and sometimes the registry and registrar records differ. When that happens, the honest result is unknown. A guessed date is worse than no date, because it gives false confidence about a renewal nobody has confirmed.

If a tool shows a domain expiry date, it is worth knowing where that date came from.

How Domainvane handles the two

Domainvane tracks both dates for each hostname you add:

  • Certificate expiry: it connects on port 443, reads the certificate, and reports days left. It also flags a hostname that doesn't match the certificate, an incomplete chain, a self-signed certificate, and one that isn't valid yet.
  • Domain-registration expiry: it looks the domain up through RDAP and records whether the date came from the registry or the registrar. If RDAP doesn't give a clear date, it shows unknown. There is no WHOIS fallback and no guessing.

Both show on one dashboard, flagged at 30, 14, 7, and 1 days before expiry, with each hostname re-checked about every 24 hours. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested).

Domainvane doesn't renew certificates or domains. Your certificate authority and registrar still do that. It also isn't an uptime monitor.

The public SSL certificate checker is a one-off certificate check for a single hostname. It doesn't look up domain registration, and the hostname you enter is not stored.

A simple routine for both

  1. List every hostname you're responsible for, and the registered domain behind each one.
  2. For each certificate, note how it renews and who owns that process.
  3. For each domain, note the registrar, the account it sits in, and whether auto-renew and the payment method are current.
  4. Check both dates on a schedule, not only when something breaks.
  5. Treat an unknown date as a task to resolve, not as a pass.

If you look after client sites, read SSL certificate monitoring for agencies. The free plan covers 3 domains; pricing lists the paid plans.