SSL certificate expired? Why it still happens, and how to make sure it never does
Auto-renewal should make expired certificates a thing of the past, yet they still take sites down. The usual causes, how to fix one in minutes, and the checks that catch the next one weeks early.
· 4 min read · By the Spot Downtime team
An expired certificate is one of the most embarrassing outages there is. The server is fine, the app is fine, and yet every visitor sees a full-screen browser warning saying your site isn't safe. Most of them leave. API clients simply fail.
With free, automatic certificates everywhere, this should be a solved problem. It isn't, and it's about to matter more: certificates are getting shorter-lived. Since March 2026, publicly trusted certificates can be valid for at most 200 days; that drops to 100 days in 2027 and 47 days in 2029. Renewals that used to happen once a year will happen every month or two, and every one is a chance to fail.
Why certificates still expire
Auto-renewal rarely fails on its own. It fails because something around it changed:
The renewal job stopped running
The site moved to a new server and nobody set up the renewal timer, the container that ran it was replaced, or the cron job was removed in a cleanup. Everything works perfectly for up to 90 days, then the site goes down.
The renewal challenge can't succeed
To prove you control the domain, the certificate authority checks a file on your site (HTTP challenge) or a DNS record (DNS challenge). Renewals fail when a new redirect, firewall rule or CDN setting blocks /.well-known/acme-challenge/, or when the DNS provider's API token used for DNS challenges has expired.
It renewed, but nobody reloaded
The new certificate is on disk, but the web server is still serving the old one from memory. Without a reload hook, renewal “succeeds” every time and the site still expires.
It renewed in one place, but not everywhere
A load balancer, a CDN, a second server or a mail server has its own copy of the certificate that nobody updates.
Nobody owns it
A certificate bought by hand two years ago, set up by someone who has since left, with reminder emails going to an inbox nobody reads.
Fixing an expired certificate right now
If you use Let's Encrypt with Certbot, the usual fix takes a minute. Renew, then reload the web server so it picks up the new certificate:
sudo certbot renew # renews anything close to expiry
sudo systemctl reload nginx # or: apache2, caddy, haproxy…
sudo certbot certificates # confirm the new expiry datesThen confirm what visitors actually see from outside, not just what's on disk:
openssl s_client -connect yourdomain.com:443 -servername yourdomain.com </dev/null 2>/dev/null \
| openssl x509 -noout -dates -subjectIf renewal fails
sudo certbot renew --dry-run. It tests the whole renewal against the staging servers without touching your live certificate, and its error message usually names the problem: a challenge that can't be reached, a DNS record that doesn't match, or a rate limit.Making sure it never happens again
1. Check the renewal job is actually scheduled
systemctl list-timers | grep certbot # systemd installs
sudo crontab -l | grep -i certbot # cron-based installsAnd make sure the renewal reloads the web server, for example with a deploy hook:
sudo certbot renew --deploy-hook "systemctl reload nginx"2. Monitor the renewal job itself
A renewal job is a cron job, and cron jobs fail silently. Add a heartbeat: the job pings a URL after each successful run, and you're alerted if it stops. The cron job monitoring guide shows how.
3. Watch the expiry date from the outside
This is the safety net that catches every cause above, including the copies on load balancers and CDNs you forgot about: check the certificate your visitors actually receive, and alert well before it expires.
Spot Downtime does this automatically for every HTTPS website monitor. It reads the certificate on each check and warns your team 14 days before it expires, once per certificate. That leaves two weeks to fix renewal calmly instead of during an outage.
4. Don't forget the domain
A certificate can't save a domain that has expired. Turn on auto-renew at your registrar, keep the payment card current, and check the expiry date with a WHOIS lookup once in a while.
5. Write down who owns it
For every certificate that isn't fully automatic: where it's installed, how it renews, and who gets the reminders. Use a shared address, not a person's inbox.
A quick checklist
- Renewal is scheduled on every server that serves the domain
- Renewal reloads the web server (deploy hook)
- Challenges aren't blocked by redirects, firewalls or the CDN
- Load balancers, CDNs and mail servers get the new certificate too
- The renewal job has a heartbeat monitor
- The live certificate is monitored from outside, with a warning weeks before expiry
- The domain itself is on auto-renew
Add your sites to Spot Downtime for free and certificate warnings come built in, alongside uptime checks and alerts.
Keep reading
- TroubleshootingWebsite down? A 10-minute checklist to find the causeA calm, step-by-step way to find out why a site is down: is it really down, DNS, the certificate, the server, or the app. Each step takes a minute and says what to do next.October 2, 2026 · 5 min read
- Troubleshooting · HTTP502 vs 503 vs 504: what each error means and how to fix itThree gateway errors, three different problems: a crashed app, no capacity, or a slow backend. How to tell them apart, where to look first, and what Cloudflare's 52x codes mean.October 2, 2026 · 4 min read