All features
TLS

SSL/TLS certificate monitoring with expiry alerts and an A+–F grade

Expired certificates are the most avoidable outage there is. PulseTrace watches every certificate's expiry, chain, revocation status and protocol configuration on each check, warns weeks ahead, and grades the whole TLS setup so a weak cipher or a missing HSTS header is visible before an auditor finds it.

A plain TLS monitor answers the basic question — does the handshake succeed, and when does the certificate expire? The SSL/TLS Security monitor goes further: protocol versions and cipher suites, certificate chain and trust (including CAA issuer alignment), OCSP revocation, and the HTTP security headers served over that connection roll into one A+–F grade.

You choose how strict the grade is. Low scores the transport only, Medium adds headers, High counts everything; whatever a mode excludes is still checked and shown as report-only, so nothing is hidden, only weighted.

  • Expiry alerts at the lead time you set per monitor (7 days by default), to any destination.
  • Chain & revocation — broken intermediates, untrusted roots and OCSP-revoked certificates are caught, not just expiry.
  • Grade-change alerts the day a header disappears or a weak cipher appears.
  • Certificate Transparency watch (Pro) flags certificates issued for your names that you didn't order.
app.pulsetrace.app · ssl certificate monitoring

How it works

  1. 1Add a TLS or SSL/TLS Security monitor for the hostname.
  2. 2Each check inspects the certificate, chain, revocation and protocol; the security monitor also grades headers, cookies and CORS.
  3. 3Expiry warnings fire at the lead time you set; grade changes open a change on the timeline and alert your destinations.

Plan availability

TLS monitor on every plan · SSL/TLS Security grading on Team and above · Certificate Transparency and look-alike watch on Pro and above.

Compare plans →

Questions about ssl certificate monitoring

How far ahead do expiry alerts fire?
At the lead time set on the monitor — 7 days by default, and most teams raise it to 30 for certificates they renew by hand. The alert goes to the monitor's destinations like any other.
Do you check certificates that aren't on HTTPS?
Yes — the TLS monitor works against any TLS port (SMTP with STARTTLS, IMAP, databases with TLS), not only 443.
What does the grade cover?
Protocol versions, cipher suites, key exchange, certificate chain and trust, CAA alignment, revocation, and — on Medium and High — HTTP security headers, cookie flags, CORS and redirect behaviour.