SSL certificate and domain expiry monitoring for agencies
When a client's certificate or domain lapses, their customers see a warning page or nothing at all, and the client calls you. It rarely matters that the certificate authority or the registrar was technically responsible. You built the site, so it looks like your miss.
Domainvane keeps a list of your client hostnames and checks two things for each one: when the TLS certificate expires and when the domain registration expires. Everything shows on one dashboard, so you can see what needs attention this week before anyone else does.
Start free with 3 domains. No card required.
Why agencies lose track
Most agencies don't forget renewals on purpose. Responsibility gets spread out:
- Certificates renew automatically through hosts, CDNs, and ACME clients, until a DNS change, a host move, or a firewall rule quietly breaks validation.
- Domains sit in a mix of registrar accounts: yours, the client's, a previous agency's, a freelancer's who left.
- A spreadsheet of dates is accurate the day you build it. It doesn't notice a certificate that was replaced with a shorter one, or a name that no longer matches the certificate.
Certificate lifetimes are also getting shorter. Under CA/Browser Forum Ballot SC-081v3, publicly trusted TLS certificates issued from 15 March 2026 can be valid for at most 200 days, falling to 100 days in 2027 and 47 days in 2029. More renewals across the same number of clients means more chances for one to slip.
What Domainvane checks
TLS certificates on port 443. For each hostname: days left until expiry, whether the hostname matches the certificate (including single-label wildcards), whether the chain is complete, and whether the certificate is self-signed or not yet valid.
Domain-registration expiry through RDAP. Domainvane looks up the registration expiry using RDAP and records whether the date came from the registry or the registrar. If the date is missing or ambiguous, the result is unknown. There is no WHOIS fallback and no guessed date. An unknown is shown as unknown so you can follow it up, rather than hidden behind a number that looks reassuring.
For background on why these are separate, see domain expiry vs SSL expiry.
How it works day to day
Add your list. Paste hostnames separated by newlines, commas, or spaces. Each one is normalized (lowercase, IDNA) and deduplicated, and comes back marked added, duplicate, invalid, or over your plan limit.
Checks run on a schedule. A healthy hostname is checked about every 24 hours. When a certificate has 7 days or fewer left, or a check is failing, the next check comes sooner, about 6 hours later.
Status, without the noise. Each hostname is flagged on your dashboard at 30, 14, 7, and 1 days before expiry, and after 3 consecutive failed checks. The same incident isn't repeated inside a 24-hour cooldown.
Email alerts when something needs attention. Those same threshold and failure results can go out by email, so you don't have to remember to open the dashboard. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested), so it's worth a quick look at the dashboard now and then as well.
Pause without deleting. Paused hostnames stay on the account and count toward your cap, but aren't checked until you unpause them. Useful when a client project is on hold.
Client report pages (Agency and Agency+)
On the Agency and Agency+ plans you can publish a read-only status page for a chosen set of a client's hostnames. It lives at a Domainvane /r/ link. The link works as a bearer token: anyone who has it can view the page, so share it only with the client, and revoke it when you need to.
These pages are not white-label. They don't carry your branding and can't run on your own domain.
What Domainvane is not
Being clear about this saves you a signup if it isn't the right tool:
- Not an uptime monitor. It doesn't check whether pages load, measure response times, or provide status pages for outages.
- Not a renewal service. Your certificate authority still issues certificates and your registrar still renews domains.
- Not a WHOIS tool. Domain dates come from RDAP only.
- Not a team or developer platform. There are no team seats, no public API, no SMS, and no Slack app.
If you need uptime monitoring, use a dedicated uptime tool alongside Domainvane.
Plans
Every plan uses the same checks and the same alert rules, and every plan includes email alerts (inbox placement is not guaranteed for every provider). Plans differ by how many domains you can add, which webhook channels are included, and client report pages. Prices are monthly, in US dollars.
| Plan | Price | Domains | Also includes |
|---|---|---|---|
| Free | $0 | 3 | Dashboard monitoring, email alerts to external inboxes including Gmail |
| Solo | $9/mo | 25 | Adds 1 generic JSON webhook |
| Agency | $29/mo | 150 | Adds generic JSON webhook, Slack-compatible webhook, up to 50 client report pages |
| Agency+ | $79/mo | 750 | Adds generic JSON webhook, Slack-compatible webhook, up to 200 client report pages |
Paid plans are month-to-month, with checkout handled by Stripe. See all plans for billing, downgrade, and cancellation details.
Try a single check first
If you want to see what Domainvane reads from a certificate before adding a list, use the free SSL certificate checker. It checks one hostname on port 443 and shows days left, issuer, SAN, and the chain the server presented. The hostname you enter is not stored. The checker is a one-off; it doesn't add anything to an account or watch the site afterward.
For a refresher on reading those results, see how to check when an SSL certificate expires.
Getting started
- Create a free account and add up to 3 client hostnames.
- Wait for the first checks to land on your dashboard.
- Review anything marked expiring, failing, or unknown.
- When the list outgrows the free plan, move to Solo, Agency, or Agency+.
Start free with 3 domains.