Every check that can be made from the outside.
CertMoni runs every check that can be made from the public internet, using the same TLS handshake a browser makes plus public data sources. You add the hostnames; we never need your private keys or access to your servers. Here is everything we watch for, on every plan.
Core
- Expiry monitoring. Leaf and intermediate expiry, not-yet-valid, and lifetimes over the CA/Browser Forum limit.
- Auto-renewal awareness. Recognises Let's Encrypt, Google, ZeroSSL, Azure, AWS and Cloudflare certificates that renew themselves, uses the CA's own renewal window where published, and warns only when a renewal is overdue.
- Monitoring board. Every cert on one board: red at the top, amber inside your window, green when healthy.
- Email alerts. Alerts to as many recipients as you like as each threshold is crossed.
Trust
- Chain and hostname validation. Missing intermediates, self-signed and untrusted chains, hostname mismatches.
- Root store status. Your root checked against Mozilla, Chrome, Apple and Microsoft via CCADB.
- Distrusted CA detection. Flags certificates from CAs that browsers have distrusted or scheduled for removal.
- CA incident watch. Open compliance incidents for your CA in Mozilla's CA Program, an early sign of mass revocation or distrust.
- Expected-issuer policy. List the CAs you use. Any certificate, served or found in CT logs, from another CA is flagged.
Cryptography
- Weak keys and algorithms. Short RSA keys, SHA-1, ROCA-vulnerable and Fermat-factorable keys.
- Key reuse detection. Spots the same private key behind many certificates.
- Shared-prime detection. A daily batch GCD across every RSA key we monitor finds keys that share a prime and can be factored in seconds.
- Cryptographic bill of materials. Your certificates, keys, algorithms and TLS settings as a CycloneDX 1.6 CBOM for audit and post-quantum planning.
- Post-quantum readiness. Probes whether your endpoint offers hybrid post-quantum key exchange (ML-KEM with X25519), the defence against harvest-now-decrypt-later.
- Key provenance fingerprinting. Classifies the likely source of every key from its modulus and exponent, tracing Infineon (ROCA), Debian weak-PRNG and other flawed generators beyond a simple pass or fail.
Compromise
- Compromised key lookup. Public key checked against published compromised-key databases.
- Revocation checks. OCSP and CRL status straight from the issuing CA, plus OCSP Must-Staple certificates served without a stapled response.
- Browser revocation lists. Every cert in your chain checked against Mozilla's OneCRL, the list Firefox uses to block revoked CAs and certificates.
- Known-compromised key blocklists. Your key checked daily against badkeys.info: Debian weak keys, keys leaked in firmware, documentation and malware, and more.
- Key blast radius. Shows every host and certificate that shares each private key, so you know what a single key compromise exposes.
- Interception-certificate detection. Watches CT logs for a valid certificate on your name whose key we never see served from your addresses, the fingerprint of the man-in-the-middle interception that hit jabber.ru in 2023.
- Revocation reality matrix. Shows which clients would really reject a revoked certificate today, CRLSets, CRLite, OCSP and soft-fail, and the exposure half-life until it simply expires.
- Mass-revocation early warning. Correlates ARI windows pulled forward, fresh CA incidents and OCSP changes across your whole estate into one prioritised reissue list before a CA forces the pace.
Transparency
- Certificate Transparency compliance. Enough SCTs for Chrome and Apple CT policy.
- Unknown certificate discovery. CT logs searched daily for certificates issued for your domains that you don't know about.
- CAA mis-issuance alerts. New certificates found in CT logs checked against your CAA records: one from a CA you didn't authorise is flagged red.
- Leaked internal hostnames. Flags staging, VPN, admin and other internal names that your certificates have published in CT logs for anyone to read.
- CT canary names. Names you never use. A certificate for one in CT logs means someone controls your DNS or your CA account: flagged red at once.
- Lookalike-domain certificates. Watches CT logs for certificates on typo and homoglyph variants of your domains, the groundwork of a phishing or impersonation campaign.
DNS
- CAA checks. Warns when your CAA records would block your CA from renewing.
- Domain expiry. Your domain's registration expiry from its registry over RDAP, alerted on your thresholds.
- CAA hardening generator. Builds the tightest CAA records for each domain from the CAs you actually use, ready to paste into your zone.
- Subdomain takeover watch. Spots a hostname whose CNAME still points at a decommissioned cloud service, the gap an attacker claims to serve their own certificate from your name.
- DANE and DNSSEC. Checks TLSA records against the served certificate and confirms your zone is DNSSEC-signed, so a TLSA record can't be stripped or forged.
- MTA-STS and TLS-RPT. Confirms your mail domain publishes an enforced MTA-STS policy covering every MX, and a TLS-RPT address to receive delivery-failure reports.
- Encrypted Client Hello. Reads the HTTPS/SVCB DNS records for your endpoint and reports whether Encrypted Client Hello is published, hiding the SNI from the network.
Service
- Server software vulnerabilities. The server version in your headers matched to NVD CVEs, with anything on CISA's actively-exploited list flagged red.
- Every address checked. Each IPv4 and IPv6 address behind a hostname handshaken on its own, so one stale node in a load balancer can't hide.
- HSTS check. Flags a missing or short Strict-Transport-Security header on web endpoints.
- TLS configuration. Old protocol versions and ciphers without forward secrecy.
- Any port and mail servers. Monitor any TLS port, with STARTTLS for SMTP, IMAP and POP3.
- Change detection. Renewals, CA changes and unreachable endpoints logged and alerted.
- TLS vulnerability probes. Safe checks for TLS compression (CRIME), insecure renegotiation, and the RSA-oracle and session-ticket flaws behind ROBOT and Ticketbleed.
- CA endpoint health. Measures the uptime and latency of the OCSP, CRL and ARI endpoints in your chain, so a CA outage can't quietly break renewal or stapling.
- App pin breakage forecast. Compares the public-key pins you record for your mobile and desktop apps against the served key and the next renewal, so a reissue can't silently brick a pinned client.
Platform
- Monthly threat intelligence. Our AI agent reviews new compromise and vulnerability sources every month.
- Embeddable board. Drop the live board into your own portal with an iframe.
- AI agent report link. Every open alert and CT discovery as a private Markdown link, written for an AI agent to investigate and fix.
- Slack, Teams and webhook alerts. Every alert also posted to Slack, Microsoft Teams or your own signed webhook.
- Public status page. A public page at certmoni.com/status/<you> showing the health of the certificates you choose to share.
- Private-endpoint agent. A small script inside your network checks internal hosts we can't reach and reports back. Nothing listens inbound.
- Compliance evidence packs. Turns your scan history into downloadable evidence for PCI DSS 4.0, NIS2, DORA and Cyber Essentials, each control mapped to the checks that satisfy it.
Related: pricing, frequently asked questions and why certificate lifetimes are shrinking.