SSL Certificate FAQ
Frequently asked questions about SSL monitoring, TLS security, and certificate management
What is SSL certificate monitoring?
SSL certificate monitoring is the process of continuously checking your SSL/TLS certificates for expiration dates, security vulnerabilities, and configuration issues. It helps prevent website downtime and security warnings by alerting you before certificates expire or when security problems are detected.
MySSL.info automates this process, scanning your domains and sending notifications via email, Slack, Discord, or webhooks. This proactive approach ensures you never miss an expiring certificate.
Why do SSL certificates expire?
SSL certificates expire for important security reasons. Certificate Authorities (CAs) set validity periods, typically ranging from 90 days to 1 year, to ensure regular verification of domain ownership and to limit the impact of compromised certificates.
Regular expiration also encourages the adoption of newer, more secure cryptographic standards. When certificates expire, browsers display security warnings that can damage user trust and business reputation.
How often should I check my SSL certificate?
You don't need to check manually — that's the point of monitoring. MySSL.info re-scans each monitored domain's SSL configuration once a month, on its own day of the month, and separately checks every monitored certificate's expiry date once a day. So an approaching expiry is caught within 24 hours no matter when the last full scan ran.
The public scanner on this site runs any time, for anyone, without an account. Re-running a scan on demand from the dashboard is a paid-plan feature. Security-header re-scans run more often, and that cadence does depend on your plan — weekly on Free, daily on Pro, hourly on Business and Enterprise.
What is TLS security?
TLS (Transport Layer Security) is the successor to SSL and is the cryptographic protocol that secures communications over computer networks. When you see HTTPS in your browser, TLS is encrypting the connection between your browser and the website.
TLS security involves proper certificate configuration, strong cipher suites, and up-to-date protocol versions. MySSL.info scans for TLS vulnerabilities like BEAST, POODLE, Heartbleed, and other known security flaws.
What does an SSL grade mean (A+, A, B, C, F)?
SSL grades indicate the security level of your certificate configuration:
- A+ Excellent security with features like HSTS enabled
- A Strong security with good configuration
- B Minor issues that should be addressed
- C Significant security weaknesses present
- F Critical vulnerabilities requiring immediate attention
MySSL.info provides detailed recommendations to improve your grade.
How do I renew my SSL certificate?
To renew your SSL certificate, follow these steps:
- Generate a new Certificate Signing Request (CSR) from your server
- Submit the CSR to your Certificate Authority or use automatic renewal with services like Let's Encrypt
- Complete domain validation (email, DNS, or HTTP verification)
- Download and install the new certificate on your server
Many hosting providers offer automatic renewal. MySSL.info alerts you well before expiration so you have plenty of time to renew.
What happens when an SSL certificate expires?
When an SSL certificate expires, browsers display prominent security warnings like "Your connection is not private" or "NET::ERR_CERT_DATE_INVALID". Most users will not proceed past these warnings, resulting in:
- Lost website traffic and potential customers
- Revenue loss from abandoned transactions
- Damage to brand reputation and user trust
- Potential search engine ranking penalties
- Broken API integrations and automated systems
This is why proactive SSL monitoring is essential for any business with an online presence.
What are the different types of SSL certificates?
There are several types of SSL certificates, each suited for different needs:
Domain Validation (DV)
Verifies domain ownership only. Quickest to obtain, ideal for blogs and personal sites.
Organisation Validation (OV)
Verifies business identity. Provides more trust indicators for commercial websites.
Extended Validation (EV)
Requires extensive verification. Displays organisation name in some browsers for maximum trust.
Wildcard Certificates
Secures a domain and all its subdomains with a single certificate.
MySSL.info monitors all certificate types with the same comprehensive security checks.
How does MySSL monitor SSL certificates?
MySSL.info uses advanced scanning technology powered by testssl.sh to thoroughly analyse your SSL/TLS configuration. Our scans check:
- Certificate validity and expiration dates
- Certificate chain completeness and trust
- Protocol versions (TLS 1.2, TLS 1.3, deprecated protocols)
- Cipher suite strength and security
- Known vulnerabilities (Heartbleed, POODLE, BEAST, etc.)
- HSTS and other security headers
Full SSL re-scans are scheduled monthly on every plan, on a per-domain day of the month; paid plans can also re-run one on demand. Certificate expiry is checked separately every day. Results are stored for trend analysis and compliance reporting for as long as your plan's history window allows — see pricing.
Is MySSL free to use?
Yes — in two different ways. The one-off scanners need no account at all: SSL grade, security headers, email authentication, DMARC and certificate search all run for anyone.
The Free plan adds ongoing monitoring and does not expire:
- 2 monitored domains
- Monthly SSL re-scans + daily expiry checks
- Weekly security-header re-scans
- 30 days of scan history
- Email notifications
- 1 uptime monitor (60-minute checks)
- 1 Blastline server
- API access
For more domains, faster header scans, longer history, more monitored servers and integrations (Slack, Discord, Telegram, webhooks) there are Pro, Business and Enterprise plans. Paid subscriptions aren't being charged during the beta, so every account currently runs at no cost — see pricing for the full comparison.
What integrations does MySSL support?
MySSL.info integrates with popular communication and DevOps tools:
Receive certificate expiry alerts and security notifications directly in your team's communication channels. The REST API is available for integrating SSL monitoring into your existing infrastructure and CI/CD pipelines. Email alerts work on every plan; the other channels need a paid plan.
How do I get SSL expiry alerts?
Getting SSL expiry alerts with MySSL.info is simple:
- Create a free MySSL.info account
- Add your domains to monitor
- Configure your notification preferences (email, Slack, Discord, Telegram or webhook)
- Set the alert threshold on each domain — how many days before expiry you want to hear about it (30 by default)
We check every monitored certificate once a day and alert you as soon as its remaining life drops to or below your threshold, then repeat at most once every three days until it's renewed — so an unrenewed certificate keeps reminding you without flooding your inbox. No technical expertise required.