ssl

The silent killer of trust: expired SSL certificates

An expired SSL certificate doesn't show a polite warning anymore — it shows a full-screen 'this site is dangerous' page that scares off every visitor. Here's how it happens, why your eyes won't catch it, and what to do about it.

MyUptimeBot Team · December 10, 2025 · 3 min read · For site owners

What visitors actually see

When your SSL certificate expires, this is what a brand-new visitor sees in Chrome:

Your connection is not private. Attackers might be trying to steal your information from yoursite.com. NET::ERR_CERT_DATE_INVALID.

It takes up the whole screen. The “back to safety” button is large and inviting. The “Advanced” link that lets the visitor proceed anyway is buried, and the language used in that flow tells them in plain English that proceeding is unsafe.

Most visitors hit back. Some hit the X. Almost none decide to “proceed unsafely” to your e-commerce site. The result is silent, total traffic loss — every conversion, every sign-up, every contact form, gone.

And here’s the worst part: you won’t see it yourself. Your browser remembers you’ve trusted the site before. So your own visits look completely normal.

Why renewal is supposed to be solved

Most modern hosts auto-renew certificates. Let’s Encrypt renews every 90 days. Cloudflare manages it for free. Vercel, Netlify, Render — all of them handle it.

So why does this still happen? A few recurring reasons:

  • Auto-renewal silently fails. The cron job didn’t run. The DNS record changed. The domain ownership challenge timed out.
  • You moved a domain. New host, didn’t reconfigure SSL, certificate expired on the old setup.
  • Manual certificates. Some setups (Apache configs from years ago, hand-rolled nginx, in-house ops) use bought certificates that don’t auto-renew. Whoever bought them left the company.
  • The wildcard expired. You renewed your main domain but the wildcard cert covering *.yoursite.com didn’t.
  • Subdomains forgotten. The shop runs on a separate SSL cert from the marketing site. The marketing site renewed. The shop didn’t.

The certificate doesn’t care that you intended to renew it. The day it expires, it expires.

The 14-day rule

Every certificate has an expiry date, and you can check it externally — no access to the server required. If you check that date every day, you have all the warning you could want.

A good practice:

  • 30 days out — get a heads-up. There’s no panic, you just know it’s coming.
  • 14 days out — second alert, the “no really, this is a thing you need to do” reminder.
  • 7 days out — daily alerts until renewed.

That cadence is what most monitoring tools (including MyUptimeBot) provide out of the box. The point is to never be surprised.

Why “we’ll just have a renewal calendar reminder” isn’t enough

We’ve seen this fail in three predictable ways:

  1. The person who set up the reminder leaves the company. Reminder still goes to their old email.
  2. The reminder gets snoozed because “it’s not urgent yet” and then forgotten.
  3. The auto-renewal supposedly works, so the reminder gets dismissed without verification.

A monitoring bot doesn’t have any of those problems. It checks the actual expiry date pulled from the live certificate, not your calendar’s idea of when it should expire.

What “checking the cert” actually means

Behind the scenes, it’s not complicated. When your monitor checks https://yoursite.com, the server presents its certificate as part of the TLS handshake. The cert includes a Not After field — that’s the expiry date.

A monitoring service reads that date, compares it to today, and alerts you when the gap shrinks below your threshold.

There’s no extra access required, no certificate authority API to integrate with, no agent to install on your server. The cert is already public information that your browser checks on every page load.

A small caveat

If your site has CDN/edge caching (Cloudflare, etc.) in front of it, the certificate the monitor sees is the edge certificate, not your origin certificate. That’s usually what you want — visitors hit the edge cert too — but it means an expired origin cert won’t get caught.

For most sites, monitoring the edge cert is the right call. If you have a reason to monitor the origin separately, set up a second monitor pointing at the origin directly.

The takeaway

SSL expiry is one of the few outage causes that is 100% predictable and 100% preventable. The information you need (the expiry date) is freely available. The lead time you have (90 days for Let’s Encrypt) is generous. The fix (renew the cert) is well-understood.

The only thing that goes wrong is forgetting. A monitoring bot doesn’t forget.

Set up SSL monitoring →

MyUptimeBot
Watching the internet

We build a friendly bot that watches your websites every 30 seconds and alerts you the moment something breaks. Notes here come from running that infrastructure, talking to the people who depend on it, and reading the postmortems no one publishes.

Stop finding out from customers.

One monitor, free forever. A friendly bot doing the worrying for you.