Feature

Three checks, one outcome

SSL monitoring catches more than expiry failures.

PageLantern tests the certificate customers receive and keeps the evidence connected to alerts, incidents, and recovery.

Expiry, hostname, and certificate-path validations converging into one trusted customer result.
Public endpoint evidence: expiry, hostname fit, and trusted path.

Expiry window

The certificate is inside the configured renewal threshold.

Early warning

Hostname mismatch

The certificate does not match the monitored host.

Invalid

Untrusted chain

The presented certificate path does not build to a trusted root.

Invalid

Certificate and domain coverage

Two renewal risks, with the right evidence for each.

Certificate checks inspect the public TLS endpoint. Domain checks read registry data. PageLantern keeps both deadlines visible without pretending they are the same signal.

Certificate checks

Inspect what customers actually receive.

  • Expiry warning window from 1 to 365 days
  • Certificate hostname match
  • Trusted certificate path

Domain monitoring

Track the registry-provided renewal date.

  • RDAP lookup where registry data is available
  • WHOIS fallback when needed
  • Renewal warnings alongside site health

Registry-data caveat: Domain dates are third-party information and may be stale, cached, rate-limited, or wrong. Verify important renewals with the registrar.

Example result

A warning with enough context to act.

Illustrative values show how expiry evidence can stay separate from certificate validity.

Target
checkout.example.com
Expires in
21 days
Warning threshold
30 days
Hostname
Matches
Certificate path
Trusted
Outcome
Early warning

Next step

Set the renewal window before it becomes urgent.

FAQ

Frequently asked questions

How far ahead does PageLantern warn about certificate expiry?

You can set the SSL expiry warning threshold from 1 to 365 days, based on the time your renewal and deployment process needs.

Does it check certificate validity, not just the expiry date?

Yes. SSL monitoring checks hostname match, the trust chain, and certificate validity against the public endpoint, so a certificate that is present but invalid is still flagged.

Can I track domain expiration too?

Yes. Domain monitoring reads RDAP data and falls back to WHOIS when needed. Registry data can be stale, cached, rate-limited, or wrong, so important renewals should still be verified with the registrar.