An expired certificate is a full outage with a scary warning page. PylonMon counts down every certificate's expiry, validates the chain like a real client, and pages you while there's still time to fix it calmly.
First 3 domains free · Nothing to install · No credit card
# add a domain — the certificate and its chain, checked three times a day: api.example.com — Certificate valid, 38 days left · chain verifies ✓ # and you're paged while it's still a task, not an outage: example.com: certificate expires in 12 days shop.example.com: missing intermediate certificate sso.example.com: chain changed — intermediate reissued, RSA → ECDSA
Every watched domain's certificate is checked three times a day with a running days-left count. On paid plans, every HTTPS uptime monitor also gets an automatic daily check that pages 14 days and again 3 days before expiry — nothing to configure.
“Not expired” isn't “working.” We verify the chain the way a strict client does and name the problem: self-signed, private CA, missing intermediate, or a hostname the certificate doesn't cover.
Email, Slack, Discord, SMS, voice, webhooks — with escalation ladders on every plan, and on Enterprise a BYO-AI agent that picks up the alert and starts the fix.
A certificate can stay perfectly valid while the chain underneath it changes: your CA reissues an intermediate, or a renewal quietly switches from RSA to ECDSA. Browsers shrug. Pinned clients, older TLS stacks and Windows/AD integrations break — and every expiry checker on the market stays green, because nothing expired.
PylonMon learns your chain's composition on the first scan and pages you the moment it drifts, with a before/after diff of exactly which certificate, signature algorithm or key changed. An intentional change is one click to accept as the new baseline. The same scan warns when an intermediate is about to expire — the certificate everyone forgets to watch, which takes every leaf under it down at once.
The classic quiet break is the missing intermediate: browsers cache intermediates, so the site looks
fine on your laptop — while curl, mobile apps, payment webhooks and mail servers are refusing the
connection right now. Automated renewal fails the same way: the cron job that renews your Let's Encrypt
certificate breaks silently, and the 30-day window just erodes until customers see the warning page. A
countdown watched from outside is the guard rail for both.
The same three-a-day scan also watches DNS and mail records for changes, SPF/DMARC enforcement, Spamhaus blocklist reputation, and (once you verify ownership) open ports — the full attack-surface picture →
Yes — the free plan includes 3 exposure assets, each with certificate + chain checks and full alerting. Paid plans (from $9/mo) raise the asset count and add the automatic daily expiry check on every HTTPS uptime monitor. See pricing →
We check the certificate actually served for the exact hostname you watch — including whether that name is covered. Watch each hostname that matters; a wildcard that doesn't cover a subdomain is precisely the mistake this catches.
We'll tell you a cert is self-signed or from a private CA rather than pretend it's fine — if that's deliberate, the matching uptime monitor has an “ignore certificate errors” switch so you keep the uptime signal without the noise.
First 3 domains free. No credit card.