Skip to main content
HostRepute Logo
Certificate Monitoring

TLS expiry alerts for every endpoint

HostRepute watches HTTPS, raw TLS, STARTTLS, CAA, hostname validity, chain health, fingerprint drift, and load balancer split-brain from cloud probes or private agents.

Coverage model

Public certificates and private-network endpoints use the same alert pipeline

Certificate profiles define warning thresholds, event types, resolved-IP behavior, interval, and optional private agent routing.

Create monitor

Add the host, protocol, port, SNI override, and certificate profile.

Run checks

Cloud workers or a private agent execute scheduled checks based on plan interval and profile routing.

Alert changes

Alertable events are deduplicated and sent through configured HostRepute alert destinations.

Included checks

Built for renewal, integrity, and mail-protocol visibility

Certificate monitoring is separate from blacklist monitoring so TLS state can have its own checks, history, alerts, and API surface.

Expiry thresholds

Default warning windows at 60, 30, 14, 7, and 1 day help teams react before renewal risk becomes an outage.

STARTTLS coverage

SMTP, IMAP, POP3, LDAP, and FTP STARTTLS checks catch non-HTTP certificate failures.

CAA and hostname validation

CAA, hostname match, chain validity, signature algorithm, and SAN data are recorded per check.

Fingerprint drift

Fingerprint changes are detected so load balancer and certificate rotation surprises become visible.

Private agents

Internal endpoints can be checked by scoped bearer-token agents without exposing them publicly.

API checks and callbacks

Developer API tokens can start asynchronous certificate checks and receive signed completion callbacks.

Plan limits

Active certificate monitor slots are subscription-backed

Plans limit active certificate monitor slots and schedule interval. Manual/API certificate checks use the HostRepute credit system.

Professional

Active certificate monitor slots
20
Interval
24h

Business

Active certificate monitor slots
75
Interval
12h

Enterprise

Active certificate monitor slots
250
Interval
6h

Certificate monitoring questions

What certificate protocols can HostRepute monitor?

HostRepute monitors HTTPS, raw TLS, and STARTTLS endpoints for SMTP, IMAP, POP3, LDAP, and FTP.

Does certificate monitoring include CAA checks?

Yes. Certificate checks include CAA validation alongside hostname, chain, expiry, algorithm, fingerprint, and load balancer drift checks.

Can HostRepute check private certificates?

Yes. Private certificate agents can poll assigned certificate profiles and report checks from inside your network.

Watch certificates before they become incidents

Create a monitor for public TLS, STARTTLS mail services, or private endpoints routed through an agent.

Start your 14-day free trial