CloudSpex

Domain health guide

SSL certificate expiry checklist

Certificate outages often appear when renewal, DNS, CDN, and origin ownership are not reviewed together. Use a repeatable checklist before a certificate reaches its renewal window.

Use the SSL Certificate Checker

Know who owns renewal

Document whether the certificate is managed by a hosting provider, CDN, load balancer, certificate service, or internal platform. Renewal failures are harder to resolve when the operator does not know which system holds the certificate lifecycle.

Also record the hostname coverage. A certificate that works for the apex domain may not cover www or another hostname used by customers.

Check HTTPS and DNS together

A certificate can be valid in one control plane but unavailable to visitors if DNS points to the wrong endpoint or a proxy routes traffic incorrectly. Confirm the public hostname, HTTPS reachability, and any redirect path after a change.

The current CloudSpex SSL checker reports certificate validation and HTTPS availability. It does not display expiry dates or days remaining, so use the certificate provider for expiry scheduling.

  1. Identify the certificate owner and renewal method.
  2. Confirm which public hostnames are covered.
  3. Check that DNS resolves to the intended public service.
  4. Verify HTTPS after renewal or proxy changes.
  5. Keep a monitoring and escalation owner for future changes.

Plan for change windows

Renewal is not only a certificate task. It can involve DNS validation, a CDN setting, an origin deployment, or a proxy. Schedule changes where they can be checked promptly.

If users report browser warnings, capture the hostname and time before changing settings. That makes it easier to distinguish a certificate problem from a DNS or routing problem.

What a public check cannot confirm

A public check can assess the response currently reachable for a hostname. It cannot confirm your renewal calendar, internal certificate inventory, private key handling, or every client-specific path.

Use it as a post-change signal, not as a substitute for certificate ownership and renewal management.

Frequently asked questions

Does CloudSpex show days until expiry?

No. The current public checker reports certificate validation and HTTPS availability, not an expiry countdown.

Can HTTPS work while the certificate still has a problem?

Yes. HTTPS reachability and certificate validation are related but distinct public signals.

Does the checker modify certificates?

No. It performs a limited, read-only public check.

Use public checks as a starting point

CloudSpex reads limited public-facing signals. It does not change DNS, website, certificate, or email settings. Confirm the responsible provider and test relevant changes before applying a remediation.