Cert lifetimes drop to 47 days by 2029

Nothing you own expires by surprise.

ExpirySentry finds every certificate, domain, email-security record and Microsoft credential your company has — including the ones nobody automated — and tells the right person before it breaks.

https://
Results in about 30 seconds No signup, no agents Read-only
Why now

Manual renewals are about to happen 8× as often.

Spreadsheets and calendar reminders worked when certs lasted a year. They won't at 47 days.

398d
Until Mar 2026
200d
Since Mar 15, 2026
100d
From Mar 15, 2027
47d
From Mar 15, 2029

Maximum public TLS certificate lifetime under CA/Browser Forum Ballot SC-081.

What we watch

One inventory for everything that expires.

Built from public data you can't hide from, so you see what an attacker — or an outage — sees first.

Every TLS certificate

We pull every cert ever issued for your domains from public Certificate Transparency logs, then handshake each live endpoint — including VPNs, mail servers and odd ports nobody remembers.

Domain registrations

Registry expiry, registrar, transfer lock and nameserver changes for every domain you own. A surprise nameserver change gets a high-priority alert.

Email authentication

SPF (including the 10-lookup limit), DKIM, DMARC, MTA-STS and TLS-RPT — checked continuously, with plain-English fixes.

New subdomains + takeovers

New hostnames show up in CT logs the moment someone issues a cert. We flag them, and catch CNAMEs pointing at deleted cloud resources before someone else claims them.

Exposed services

Weekly checks for RDP, SMB, databases and other ports that should never face the internet — on domains you've verified you own.

Microsoft Entra secrets + SAML

Read-only Graph access lists every app-registration secret, certificate and SAML signing cert, so SSO and integrations don't die on a Tuesday.

How it works

Live in five minutes. No agents, no tickets.

Enter your domain

We map certificates, hostnames, DNS and email posture from public data in under a minute. Nothing to install.

Verify with one DNS record

Prove ownership and we switch on live checks for every host, exposure checks and takeover detection.

Route alerts to owners

Assign an owner per asset. Alerts go to them plus Slack, Teams, email or your ticketing webhook — at 60, 30, 14, 7, 3 and 1 days.

The outages we prevent

It's never the cert you're watching.

The VPN cert someone renewed by hand

It was a 398-day cert. Nobody automated it, the person who did it left, and remote work stopped at 8:02 AM.

The SAML signing cert

Entra rolls a three-year cert. Three years later, nobody remembers, and every user is locked out of the app at once.

The client secret behind an integration

A two-year app secret expires and payroll, CRM sync or backups quietly stop. You find out from an angry email.

The domain on an expired card

Auto-renew was on, but the card wasn't. Website and email go dark, and the name is up for grabs.

Pricing

Priced like a tool, not a PKI project.

Enterprise certificate-lifecycle suites run tens of thousands a year. Start in minutes, cancel any time.

Starter

For a single IT team with a handful of domains.

$199 /month

or $1,990/year

  • 5 root domains, 250 hostnames
  • Certificate Transparency discovery
  • TLS, domain, DNS and email-auth checks every 12 hours
  • Email, Slack and Teams alerts
  • Owners per asset + weekly digest
  • 3 team seats
Start 14-day free trial

Business

For multi-brand orgs, MSPs and regulated teams.

$999 /month

or $9,990/year

  • 100 root domains, 10,000 hostnames
  • Hourly checks
  • 10 Entra tenants
  • REST API + CSV/JSON export
  • Unlimited seats
  • Priority support with a 4-hour response target
  • Onboarding call included
Start 14-day free trial

More than 100 domains, MSP pricing, or need a security review? Talk to us.

FAQ

Questions IT teams ask us

Do you need access to our servers or network?

No. Everything is outside-in: public Certificate Transparency logs, DNS, the registry, and the same TLS handshake a browser makes. The optional Microsoft add-on is read-only (Application.Read.All) and you can revoke it any time.

Why verify the domain?

So we only actively test infrastructure you own. Until you verify, we limit ourselves to passive data plus your main website. Verification is a single TXT record — or a file on your web server.

We already use ACME / Let's Encrypt. Do we need this?

ACME handles the easy certs. The outages come from the ones it doesn't: appliances, VPNs, load balancers, vendor-hosted subdomains, SAML certs, app secrets, and the domain itself. We also catch ACME jobs that silently stopped renewing.

How is this different from an EASM platform?

We focus on the expiry and misconfiguration problems that cause real outages, at a fraction of enterprise pricing, with setup in minutes rather than a sales cycle.

What happens after the trial?

14 days, full Pro features, no card required. If you don't pick a plan, monitoring pauses and nothing is charged. Your inventory stays saved for 30 days.

Can we pay annually or by invoice?

Yes. Annual plans include two months free. Business customers can pay by invoice — contact us.

What expires next on your domain?

Run a free scan. You'll see your certificates, registration date, email-security grade and anything already in the danger zone.

https://