Enter a domain and get the full picture in seconds: when the certificate expires, whether the chain is trusted, whether the hostname matches - the things that break at 2 AM on a Saturday. No signup, no email gate.
The check connects to port 443 of the host you enter (with SNI), retrieves the live certificate exactly as a browser would, and reports: days until expiry, the full issuer chain and whether it's trusted, hostname match against the certificate's names, the negotiated TLS protocol and cipher, and all subject alternative names. Broken configurations are the interesting case - expired, self-signed, wrong-host, and incomplete-chain certificates are all reported rather than hidden behind a generic error.
Nobody forgets renewal on purpose. Certificates expire because the renewal automation broke silently months ago, because the cert on the load balancer isn't the one certbot renews, or because the one legacy subdomain wasn't in the automation at all. The fix isn't remembering harder - it's a monitor that counts down and tells you at 30, 14, and 7 days, on a channel someone actually reads.
AlertKick's free tier monitors this certificate continuously - alerts to email, Telegram, or Slack before it expires, plus uptime on the same monitor. 10 monitors free, no card, commercial use welcome.
Monitor this certificate - freeAlso useful: domain expiry checker - the other renewal that takes sites down.