My cert auto-renews, so do I still need SSL expiry alerts?
Q: We use auto-renewal. Setting up expiry monitoring feels redundant. Is it?
A: Here's a case that changed my mind. An agency managed 80 client domains, all on auto-renew, all assumed safe. They added expiry checks anyway, with alerts at 30, 14, and 7 days remaining.
Within the first quarter, 3 certs tripped the 14-day alert. The cause wasn't the renewal logic — it was a DNS validation record a client had deleted, so the renewal silently failed while the old cert kept serving. Without the alert, all 3 would have hit live expiry and thrown browser warnings to real visitors.
The follow-up: which threshold caught them? All 3 fired at 14 days but were only fixed because a human saw the 7-day escalation. So set at least two thresholds, and route the last one to a channel someone actually watches.
Got a question? Drop it in the comments.
Pingback Clinic
@PingbackClinic
My cert auto-renews, so do I still need SSL expiry alerts?
Этот пост опубликован в Telegram-канале Pingback Clinic. Подписаться можно по ссылке: @PingbackClinic.