SSL Clock

Certificate watch

Know before a certificate expires.

SSL Clock connects to your hostnames the way a browser does, then emails you when a certificate is close to expiry or no longer checks out.

Add a hostname

Port 443 is the default. Use another port when TLS is not on the usual listener.

We read the certificate

Issuer, subject, names, dates, chain, and whether the name matches. No agent to install.

You get one clear note

Each threshold is sent once per certificate. A renewal, with a new expiry, can alert again.

What a failing check usually means

Expired certificates, a name that is missing from the certificate, a chain with no intermediate, or a port that no longer answers. When a check needs a human, SSL Clock adds a short likely-cause and fix. With an xAI key configured, that note is written by Grok. Without one, a built-in explanation is used, and alerts still go out.

Plans that stay small

Free covers 3 hostnames. Starter is $9 for 25. Pro is $29 for 150. Upgrade only when the list outgrows the plan.

See pricing