Certificate expiry checker
Check when a certificate expires, who issued it, and how many names it covers.
For example: · No account, no email, no daily limit.
Also free, no account:Domain Rating checkerAI crawler checkerllms.txt checkerAll tools
What this reads
Domduck opens a TLS connection to the domain and reads the certificate it is actually serving: the issuer, the expiry date, how many days are left, and how many names the certificate covers.
That is different from reading a certificate transparency log. A log tells you what was issued. A handshake tells you what is being served right now, and those two answers disagree more often than people expect.
“I automate renewal, so I do not need this”
This is the most common answer on every forum thread about certificate monitoring, and it is half right. Automated renewal is correct and you should have it. It is not a reason to stop looking.
Automation fails quietly. A renewal hook fails and the exit code is swallowed. A DNS challenge stops working after a nameserver change. A certificate renews correctly and the service never reloads, so the old one keeps being served until it expires. A load balancer holds a copy nobody remembers. In every one of those cases the renewal log looks fine and the edge is serving a certificate that is about to expire.
Monitoring the renewal is monitoring the thing you control. Reading the handshake is checking the thing your users get.
Let’s Encrypt stopped sending expiry emails
The expiration notification emails many people quietly relied on are gone. If that was the alarm in your setup, there is no alarm in your setup.
How many days is a reasonable warning?
Thirty days is the usual answer and it is too late to be useful on its own. A 90-day certificate that renews at day 60 should be checked continuously, because the interesting failure is not the expiry, it is the renewal that silently stopped working a month before it.
The useful signal is a certificate whose expiry date has not moved when it should have. That needs a record, not a check.
What happens after the check
The reading is written down with the date it was taken and it stays. Add the domain to a free account and Domduck reads it every day, so the series shows you the renewal happening and shows you the day it stops happening.
There is no limit on how many domains you watch. Free tiers in this category usually cap at five, which is exactly the point at which certificate monitoring starts being useful.
What else lands on the record
The same page carries the domain’s DNS records, its registration date, its popularity rank and its AI crawler policy, each with the date it was read. That combination is the reason to use this rather than a single-purpose checker.
Certificate expiry and nameserver changes are related more often than they look: a DNS challenge that stops validating after a nameserver move is one of the ways silent renewal failure starts. The other free tools read those.
Every free tool here
- Domain Rating checker
Type a domain. See its Domain Rating, its popularity rank, how old it is, when its certificate expires and which AI crawlers it blocks.
- Bulk Domain Rating checker
Paste your list, one domain per line. No account, no captcha, no daily limit.
- AI crawler checker
Check what a site tells GPTBot, ClaudeBot, PerplexityBot and five more, and whether the edge agrees with the file.
- llms.txt checker
Check whether a site publishes an llms.txt file, and whether the file is actually valid.
- Domain badges
Five embeddable badges for any domain, each linking to that domain’s own record.