Expiry window
The certificate is inside the configured renewal threshold.
Early warning
Three checks, one outcome
PageLantern tests the certificate customers receive and keeps the evidence connected to alerts, incidents, and recovery.

The certificate is inside the configured renewal threshold.
Early warningThe certificate does not match the monitored host.
InvalidThe presented certificate path does not build to a trusted root.
InvalidCertificate and domain coverage
Certificate checks inspect the public TLS endpoint. Domain checks read registry data. PageLantern keeps both deadlines visible without pretending they are the same signal.
Certificate checks
Domain monitoring
Registry-data caveat: Domain dates are third-party information and may be stale, cached, rate-limited, or wrong. Verify important renewals with the registrar.
Example result
Illustrative values show how expiry evidence can stay separate from certificate validity.
Next step
FAQ
You can set the SSL expiry warning threshold from 1 to 365 days, based on the time your renewal and deployment process needs.
Yes. SSL monitoring checks hostname match, the trust chain, and certificate validity against the public endpoint, so a certificate that is present but invalid is still flagged.
Yes. Domain monitoring reads RDAP data and falls back to WHOIS when needed. Registry data can be stale, cached, rate-limited, or wrong, so important renewals should still be verified with the registrar.