The two outages you can see coming.
A certificate expiring and a domain lapsing are the only failures in your stack that arrive on a published schedule. StatusOwl reads both schedules and counts down for you.
What the certificate says, not just whether the handshake worked.
An SSL monitor performs the TLS handshake a browser would and reads the certificate the server actually presented.
- Subject and issuer
- Which name the certificate covers and which authority signed it. A certificate that quietly changed issuer is worth knowing about.
- Not before and not after
- The full validity window, recorded as dates rather than as a countdown you have to trust. A certificate that is not valid yet fails for the same reason an expired one does.
- Days remaining
- The number you actually plan around, recalculated on every check.
- Warning and critical thresholds
- Two per-monitor numbers. Days remaining is compared against both, so a certificate is flagged as approaching expiry long before it is flagged as urgent.
- Subject
- acme.com
- Issuer
- Internet Security Research Group
- Not before
- 2026-05-14
- Not after
- 2026-08-12
- Days remaining
- 38
- Warning at
- 30 days
- Critical at
- 7 days
- Checked
- Hourly
- Domain
- acme.com
- Registration expires
- 2027-01-19
- Days remaining
- 168
- Nameservers
- 2 recorded
- Last nameserver change
- None recorded
- Checked
- Daily
The domain monitor watches the nameserver set as well as the expiry date, and flags a change.
WHOIS, read on your behalf.
A lapsed registration takes down every service on the domain at once, including the status page you would use to explain it.
- Registration expiry
- The expiry date from the domain's WHOIS record, tracked as days remaining and counted down on every check.
- Nameserver-change detection
- StatusOwl keeps the nameserver set it saw last time and tells you when it changes. An unexpected change is either a migration nobody told you about, or a domain being moved without you.
- Checked on a slow schedule
- Registration dates move on the order of months, and registrars rate-limit WHOIS. Domain monitors default to one check a day rather than one every thirty seconds — which is exactly often enough.
Flat across the ladder.
Certificate and domain monitoring is not a lever we price on. The same allowance applies whether you are on Free or on Scale.
25 certificates per organisation on every plan. It is counted per organisation, not per status page, and it does not rise with the plan.
| Included | Free | Starter | Growth | Scale |
|---|---|---|---|---|
SSL certificate expiry Subject, issuer, validity window, days remaining, warning and critical thresholds. | Included | Included | Included | Included |
Domain expiry (WHOIS) Registration expiry with nameserver-change detection. | Included | Included | Included | Included |
These monitors do not appear on your status page.
They are dashboard instruments, not page services. That distinction matters enough to spell out.
No uptime bars
An SSL or domain monitor produces no daily bar and no 30-day uptime percentage. The bars on a status page come from HTTP, ping and TCP checks — the ones that measure whether a service answered.
Not a page service
You do not attach a certificate to a service row. Expiry is something you fix in advance, not something you narrate to customers while it is happening.
But they still protect the page
When a certificate does lapse, it is the HTTP monitor in front of it that starts failing — and that is what opens the incident. Watching expiry is how you keep that from being the first time you hear about it.
Crossing a warning or critical threshold records the state against the monitor. It does not send an email, a Slack message or a webhook. The six notification channels are built and in production, but the only thing wired to trigger them today is a Watch Owl server-metric alert rule. Routing check results to your channels — expiry included — is what we are building right now.
Uptime checks
HTTP, ping and TCP — the checks that decide what each service on your status page reads, and that open the incident when one stops answering.
Read moreYour status page’s own certificate
The one certificate you never have to monitor: the page’s own, issued and renewed automatically when you point a custom domain at it.
Read moreKnow about the expiry before your customers do.
Free forever on one page, with your own domain and automatic SSL. Certificate and domain monitoring included on every plan.