Monitor SSL certificates, domain expiry, and DNS/DNSSEC across all your sites. Track every DNS record change and get alerted on Slack, email, or webhook before anything lapses — so you never find out from your customers.
No reviews yetBe the first to leave a review for Certly
Maker
📌
Hi Product Hunt! 👋
Managed SSL has made certificate renewals mostly automatic — but “mostly” is the problem. Self-managed certs, forgotten subdomains, and domain registrations still expire silently. And lately there’s a bigger worry: email spoofing. Weak or missing DMARC/SPF settings let attackers send emails pretending to be your domain, and most teams don’t notice until damage is done.
That’s why I built Certly. It watches your SSL certificates, domain expiry, DNS/DNSSEC health, and email authentication posture, and alerts you on Slack, email, or webhook before anything lapses. It also tracks every DNS record change, so silent modifications don’t go unnoticed.
There’s a free plan — you can add your first domain and see results in under a minute.
I’d love your feedback — especially on what other checks you’d want monitored. Thanks for checking it out!
Report
Does Certly handle wildcard certs the same as standard ones, and what happens if I rotate a cert through your system does the alerting reset automatically or do I need to reconfigure anything?
Great questions! Wildcard certs are handled exactly the same as standard ones — Certly checks the certificate your server actually presents for the monitored hostname, and wildcard matching (e.g. *.example.com covering
Rotation needs zero reconfiguration. Certly doesn’t sit in your issuance pipeline — it observes the live cert from the outside once a day. So when you rotate, the next check simply sees the new expiry date and the countdown resets automatically. Alerts fire at 30/14/7/1 days before expiry, so after a rotation you just won’t hear from us again until the new cert approaches those thresholds. Nothing to reset, nothing to tell us.
Report
How does certly handle certificate transparency logs? Like if someone manages to issue a sneaky cert for one of my domains, can it catch that too or only stuff I've already set up?
Honest answer: not yet — but it’s on the roadmap, and you’ve picked exactly the feature I’m most excited to build next.
We already pull CT issuance data for the free public checker, but the daily monitoring currently tracks the certs your servers actually present, plus domain expiry, DNS record changes, and DMARC/SPF posture. The DNS-change alerts do cover part of the “sneaky issuance” story — most rogue certs start with a DNS or nameserver takeover, and Certly flags those the same day.
Full CT monitoring — alerting when any cert is issued for your domain that you didn’t expect, including lookalike domains — is planned. If you’d like, I’m happy to ping you when it ships.
Report
Caught a sneaky DNS record change on one of my side projects that I would have totally missed otherwise. Slack alert arrived a few minutes before the cert was set to renew, saved me an embarrassing email from a client.
Side projects are exactly where this stuff slips through — glad Certly caught it before your client did. Thanks for sharing!
Report
The DNS change history view is such a smart move, makes it dead simple to spot which tweak broke prod last week. Slack alerts on the expiry thresholds feel just right too.
That view exists for exactly that “what changed last Tuesday?” moment — glad it’s earning its keep. And good to hear the alert thresholds feel right; tuning them to be useful-but-not-noisy took a few iterations. Thanks!
Report
The fact that it watches DNSSEC alongside SSL and DNS records shows real attention to the full certificate trust chain, not just the obvious stuff. Slack and webhook alerts before expiry is exactly the kind of unglamorous infrastructure tool that saves a Friday night.
“Unglamorous infrastructure tool that saves a Friday night” might be the best description of Certly anyone has written — I may have to steal that for the landing page.
DNSSEC felt like a natural fit precisely because it fails the same way certs do: silently, on a schedule nobody is watching. A signature that doesn’t get re-signed takes your domain offline just as thoroughly as an expired cert, but almost nothing out there warns you about it. Thanks for noticing — that one took some care to get right.
Does Certly handle wildcard certs the same as standard ones, and what happens if I rotate a cert through your system does the alerting reset automatically or do I need to reconfigure anything?
@neriman91088467
Great questions! Wildcard certs are handled exactly the same as standard ones — Certly checks the certificate your server actually presents for the monitored hostname, and wildcard matching (e.g. *.example.com covering
api.example.com
) is validated the same way a browser would.
Rotation needs zero reconfiguration. Certly doesn’t sit in your issuance pipeline — it observes the live cert from the outside once a day. So when you rotate, the next check simply sees the new expiry date and the countdown resets automatically. Alerts fire at 30/14/7/1 days before expiry, so after a rotation you just won’t hear from us again until the new cert approaches those thresholds. Nothing to reset, nothing to tell us.
How does certly handle certificate transparency logs? Like if someone manages to issue a sneaky cert for one of my domains, can it catch that too or only stuff I've already set up?
@songlzkara50786
Honest answer: not yet — but it’s on the roadmap, and you’ve picked exactly the feature I’m most excited to build next.
We already pull CT issuance data for the free public checker, but the daily monitoring currently tracks the certs your servers actually present, plus domain expiry, DNS record changes, and DMARC/SPF posture. The DNS-change alerts do cover part of the “sneaky issuance” story — most rogue certs start with a DNS or nameserver takeover, and Certly flags those the same day.
Full CT monitoring — alerting when any cert is issued for your domain that you didn’t expect, including lookalike domains — is planned. If you’d like, I’m happy to ping you when it ships.
Caught a sneaky DNS record change on one of my side projects that I would have totally missed otherwise. Slack alert arrived a few minutes before the cert was set to renew, saved me an embarrassing email from a client.
@yiitellezf6fz
Side projects are exactly where this stuff slips through — glad Certly caught it before your client did. Thanks for sharing!
The DNS change history view is such a smart move, makes it dead simple to spot which tweak broke prod last week. Slack alerts on the expiry thresholds feel just right too.
@semasf8r
That view exists for exactly that “what changed last Tuesday?” moment — glad it’s earning its keep. And good to hear the alert thresholds feel right; tuning them to be useful-but-not-noisy took a few iterations. Thanks!
The fact that it watches DNSSEC alongside SSL and DNS records shows real attention to the full certificate trust chain, not just the obvious stuff. Slack and webhook alerts before expiry is exactly the kind of unglamorous infrastructure tool that saves a Friday night.
@evval588200
“Unglamorous infrastructure tool that saves a Friday night” might be the best description of Certly anyone has written — I may have to steal that for the landing page.
DNSSEC felt like a natural fit precisely because it fails the same way certs do: silently, on a schedule nobody is watching. A signature that doesn’t get re-signed takes your domain offline just as thoroughly as an expired cert, but almost nothing out there warns you about it. Thanks for noticing — that one took some care to get right.