Skip to content
On this page

Monitoring

SSL certificates

Catch certificate problems before your visitors do. No more surprise browser warnings.

What SSL checks cover

SSL checks track the validity, expiry date, and trust chain of the digital certificate that encrypts traffic between your site and its visitors. Your SSL certificate is the padlock in your browser's address bar. If it expires or breaks, browsers show a scary warning page that stops people in their tracks, and trust takes a long time to win back. DomainDash keeps an eye on your certificate so you know about issues well before they reach a single visitor.

You'll find SSL details on each site's Security sub-page.

What we check

Every time we run an SSL check, we look at several things:

  • Is a certificate present? We make sure your site actually has a certificate installed.
  • Has it expired? Certificates have a fixed lifespan. We track when yours expires and warn you in advance.
  • Does it cover the right domain? A certificate issued for example.com won't work for shop.example.com. We check that your certificate matches the domain we're checking.
  • Is the chain trusted? Your certificate is part of a chain that leads back to a trusted authority. If any link in that chain is broken, browsers won't trust it.
  • Is it self-signed? Self-signed certificates aren't trusted by browsers. We flag these so you know to switch to a proper certificate.
  • Is the connection secure? We verify that the TLS (Transport Layer Security) connection, the encryption technology behind HTTPS, is working correctly.

Each check gets a clear pass or fail, so you can see at a glance whether everything is in order — and catch a problem long before a visitor meets a browser warning.

Modern certificates have short lifespans on purpose. Let's Encrypt issues 90-day certificates, and the wider industry is moving toward shorter renewal cycles. That means a missed renewal can take your site offline within weeks, not years, which is why we surface expiry warnings well ahead of time.

Understanding your SSL data

The Security sub-page shows two cards side by side:

Certificate details

This shows the key facts about your current certificate:

  • Covers: the domain name the certificate was issued for
  • Issued by: the certificate authority (like Let's Encrypt, Cloudflare, or DigiCert)
  • Valid from / Expires: the start and end dates of your certificate's lifespan
  • Protocol: the TLS version in use (like TLS 1.3)
  • Chain: whether the certificate chain is trusted

Below these details, a lifespan progress bar shows how far through its validity period your certificate is. As it gets closer to expiry, the bar changes colour to draw your attention.

Security checks

This is a checklist showing whether your certificate passes each of the checks described above. A green tick means everything is fine; a red cross means there's a problem to look at, and you've spotted it on your own terms, not because a customer wrote in about a warning page.

When something needs attention

When a certificate moves into a warning state (for example, it's getting close to expiry), the Security page leads with an Insights summary: a plain-English explanation of what's happening and the steps to put it right.

Plan availability

Insights is available on Starter, Pro and Business. See the plan comparison.

Common SSL issues

When DomainDash flags an SSL problem, the troubleshooting section walks you through what's happening and how to fix it. The most common ones:

See all SSL troubleshooting pages for the full list.

Frequently asked questions

How early does DomainDash warn me before my SSL certificate expires?

DomainDash starts surfacing expiry warnings up to 30 days before your certificate expires: the lifespan progress bar changes colour to draw your attention. As the deadline gets closer the site moves to "Needs attention", and the most urgent alerts go out in the final week, with the most pressing in the last day before expiry.

How often does DomainDash run SSL checks?

SSL checks run a few times a day; how often depends on your plan. Certificates don't change often, so this is plenty to catch problems quickly.

Does DomainDash check SSL certificates for subdomains?

DomainDash checks the exact domain you've added as a site. To check shop.example.com, add it as a separate site, since it won't be covered by checks on example.com because SSL certificates are issued per-hostname (unless the certificate is a wildcard or covers the subdomain via Subject Alternative Names).

What does "untrusted certificate chain" mean?

Every SSL certificate is signed by an intermediate certificate, which is signed by a root certificate that browsers trust. If any link in this chain is missing or invalid, browsers can't verify the certificate and show a security warning. The most common cause is a server configured to serve the leaf certificate without the intermediate. See Certificate signed by an untrusted authority for fixes.

Can DomainDash check self-signed certificates?

DomainDash detects self-signed certificates and flags them as a problem, because browsers don't trust them and visitors will see security warnings. Self-signed certificates are appropriate for internal testing but not for production sites. Switch to a free certificate from Let's Encrypt or a paid provider for public-facing sites.

  • Domain health check for how uptime, SSL, DNS, and registration roll up into one status
  • Uptime checks for checking that your site is online and responding
  • DNS health for checking your domain's routing configuration

Start checking your sites for free

DomainDash keeps an eye on your uptime, SSL, DNS, and domain registration so you don't have to — and tells you the moment something needs your attention. Set up in under a minute, no credit card.

Last updated: 19 June 2026