SSL Monitoring and Alerts: What We Watch and How to Get Notified
A one-off check finds today’s problems. Monitoring catches tomorrow’s regressions — a deploy that drops CSP, a cert that fails to renew, or a new certificate issued for your domain that you did not expect. This guide explains what httpsornot monitors and how alerts are delivered.
Key takeaways
- Free account: monitor one domain on a weekly cadence (see current plan limits on Pricing).
- Paid plans: daily checks, history, Slack/webhooks, Certificate Transparency alerts, more domains.
- Header drops are a classic silent failure — see when a deploy drops CSP.
What we watch
- HTTPS reachability and HTTP→HTTPS redirect behaviour
- SSL/HTTPS grade and certificate validity / days until expiry
- Security headers (including HSTS and CSP)
- Optional: Certificate Transparency — new certs seen for the domain (paid)
Exact diff rules are anti-flaky (recheck before alert). Scope can be limited in account settings (e.g. only grade / cert / headers).
How you get notified
- Email — account or alert email when something changes.
- Slack / webhook — paid plans; POST a summary to your URL or Slack incoming webhook.
- One-shot cert reminder — separate from monitoring: request an email ~30 days before expiry from a check result (no account required for that reminder flow).