Find out a certificate is failing before your customers do.
CertMoni watches every public TLS certificate you run: websites, APIs and mail servers. It warns you well before one expires, is revoked or stops being trusted. You add the hostnames. We never need your keys or access to your servers.
Start a free trial · See pricing
Explore: every check we make · pricing · questions · why certificate lifetimes are shrinking.
Certificates are about to expire far more often.
The CA/Browser Forum is cutting the maximum certificate lifetime to 200 days in March 2026, 100 days in March 2027 and 47 days in March 2029. More renewals mean more chances to miss one. CertMoni watches around the clock so you do not have to.
Every check that can be made from the outside.
Core
- Expiry monitoring. Leaf and intermediate expiry, not-yet-valid, and lifetimes over the CA/Browser Forum limit.
- Auto-renewal awareness. Recognises Let's Encrypt, Google, ZeroSSL, Azure, AWS and Cloudflare certificates that renew themselves, uses the CA's own renewal window where published, and warns only when a renewal is overdue.
- Monitoring board. Every cert on one board: red at the top, amber inside your window, green when healthy.
- Email alerts. Alerts to as many recipients as you like as each threshold is crossed.
Trust
- Chain and hostname validation. Missing intermediates, self-signed and untrusted chains, hostname mismatches.
- Root store status. Your root checked against Mozilla, Chrome, Apple and Microsoft via CCADB.
- Distrusted CA detection. Flags certificates from CAs that browsers have distrusted or scheduled for removal.
- CA incident watch. Open compliance incidents for your CA in Mozilla's CA Program, an early sign of mass revocation or distrust.
- Expected-issuer policy. List the CAs you use. Any certificate, served or found in CT logs, from another CA is flagged.
Cryptography
- Weak keys and algorithms. Short RSA keys, SHA-1, ROCA-vulnerable and Fermat-factorable keys.
- Key reuse detection. Spots the same private key behind many certificates.
- Shared-prime detection. A daily batch GCD across every RSA key we monitor finds keys that share a prime and can be factored in seconds.
- Cryptographic bill of materials. Your certificates, keys, algorithms and TLS settings as a CycloneDX 1.6 CBOM for audit and post-quantum planning.
- Post-quantum readiness. Probes whether your endpoint offers hybrid post-quantum key exchange (ML-KEM with X25519), the defence against harvest-now-decrypt-later.
- Key provenance fingerprinting. Classifies the likely source of every key from its modulus and exponent, tracing Infineon (ROCA), Debian weak-PRNG and other flawed generators beyond a simple pass or fail.
Compromise
- Compromised key lookup. Public key checked against published compromised-key databases.
- Revocation checks. OCSP and CRL status straight from the issuing CA, plus OCSP Must-Staple certificates served without a stapled response.
- Browser revocation lists. Every cert in your chain checked against Mozilla's OneCRL, the list Firefox uses to block revoked CAs and certificates.
- Known-compromised key blocklists. Your key checked daily against badkeys.info: Debian weak keys, keys leaked in firmware, documentation and malware, and more.
- Key blast radius. Shows every host and certificate that shares each private key, so you know what a single key compromise exposes.
- Interception-certificate detection. Watches CT logs for a valid certificate on your name whose key we never see served from your addresses, the fingerprint of the man-in-the-middle interception that hit jabber.ru in 2023.
- Revocation reality matrix. Shows which clients would really reject a revoked certificate today, CRLSets, CRLite, OCSP and soft-fail, and the exposure half-life until it simply expires.
- Mass-revocation early warning. Correlates ARI windows pulled forward, fresh CA incidents and OCSP changes across your whole estate into one prioritised reissue list before a CA forces the pace.
Transparency
- Certificate Transparency compliance. Enough SCTs for Chrome and Apple CT policy.
- Unknown certificate discovery. CT logs searched daily for certificates issued for your domains that you don't know about.
- CAA mis-issuance alerts. New certificates found in CT logs checked against your CAA records: one from a CA you didn't authorise is flagged red.
- Leaked internal hostnames. Flags staging, VPN, admin and other internal names that your certificates have published in CT logs for anyone to read.
- CT canary names. Names you never use. A certificate for one in CT logs means someone controls your DNS or your CA account: flagged red at once.
- Lookalike-domain certificates. Watches CT logs for certificates on typo and homoglyph variants of your domains, the groundwork of a phishing or impersonation campaign.
DNS
- CAA checks. Warns when your CAA records would block your CA from renewing.
- Domain expiry. Your domain's registration expiry from its registry over RDAP, alerted on your thresholds.
- CAA hardening generator. Builds the tightest CAA records for each domain from the CAs you actually use, ready to paste into your zone.
- Subdomain takeover watch. Spots a hostname whose CNAME still points at a decommissioned cloud service, the gap an attacker claims to serve their own certificate from your name.
- DANE and DNSSEC. Checks TLSA records against the served certificate and confirms your zone is DNSSEC-signed, so a TLSA record can't be stripped or forged.
- MTA-STS and TLS-RPT. Confirms your mail domain publishes an enforced MTA-STS policy covering every MX, and a TLS-RPT address to receive delivery-failure reports.
- Encrypted Client Hello. Reads the HTTPS/SVCB DNS records for your endpoint and reports whether Encrypted Client Hello is published, hiding the SNI from the network.
Service
- Server software vulnerabilities. The server version in your headers matched to NVD CVEs, with anything on CISA's actively-exploited list flagged red.
- Every address checked. Each IPv4 and IPv6 address behind a hostname handshaken on its own, so one stale node in a load balancer can't hide.
- HSTS check. Flags a missing or short Strict-Transport-Security header on web endpoints.
- TLS configuration. Old protocol versions and ciphers without forward secrecy.
- Any port and mail servers. Monitor any TLS port, with STARTTLS for SMTP, IMAP and POP3.
- Change detection. Renewals, CA changes and unreachable endpoints logged and alerted.
- TLS vulnerability probes. Safe checks for TLS compression (CRIME), insecure renegotiation, and the RSA-oracle and session-ticket flaws behind ROBOT and Ticketbleed.
- CA endpoint health. Measures the uptime and latency of the OCSP, CRL and ARI endpoints in your chain, so a CA outage can't quietly break renewal or stapling.
- App pin breakage forecast. Compares the public-key pins you record for your mobile and desktop apps against the served key and the next renewal, so a reissue can't silently brick a pinned client.
Platform
- Monthly threat intelligence. Our AI agent reviews new compromise and vulnerability sources every month.
- Embeddable board. Drop the live board into your own portal with an iframe.
- AI agent report link. Every open alert and CT discovery as a private Markdown link, written for an AI agent to investigate and fix.
- Slack, Teams and webhook alerts. Every alert also posted to Slack, Microsoft Teams or your own signed webhook.
- Public status page. A public page at certmoni.com/status/<you> showing the health of the certificates you choose to share.
- Private-endpoint agent. A small script inside your network checks internal hosts we can't reach and reports back. Nothing listens inbound.
- Compliance evidence packs. Turns your scan history into downloadable evidence for PCI DSS 4.0, NIS2, DORA and Cyber Essentials, each control mapped to the checks that satisfy it.
Red at the top. Amber when it is time to plan.
Every certificate on one board: red when it needs action now, amber inside your planning window, green when it is healthy. Alerts go by email, Slack, Teams or signed webhook to everyone on your list.
Put the live board inside your own portal.
Embed the monitoring board in your own admin area or status page, or publish a branded public status page on your own company subdomain.
Simple pricing, per certificate.
Pay for 1, 2 or 3 years up front by PayPal. Add certificates mid-term and pay only for the time left.
- Standard — £1 per certificate per month. Every check, every certificate, £1 a domain a month.
Questions
Do you need access to my servers or private keys?
No. Everything is checked from the public internet, using the same TLS handshake any browser makes, plus public data sources.
What counts as one certificate?
Each endpoint you monitor, meaning a hostname and port, counts as one. A wildcard certificate served on three hostnames is three endpoints, because each can break on its own.
Can I monitor internal or private hosts?
Not yet. CertMoni monitors endpoints reachable from the internet. Private addresses are refused.
What happens when my plan runs out?
We email you a month, two weeks and one week before renewal. If it lapses, checks pause but your board and history stay put until you renew.
How do I pay?
By PayPal, a year or more in advance. You can buy 1, 2 or 3 years and top up with more certificates at any time.