The server may not reload
A certificate can renew on disk while the web server or proxy keeps serving the old one.
Use an outside certificate check to confirm your public website renewed correctly, then monitor the sites that should not depend on a single renewal script.
Small teams often rely on automatic Let's Encrypt renewal. That is a good start, but it does not always prove that the new certificate is deployed to the public hostname customers use.
A certificate can renew on disk while the web server or proxy keeps serving the old one.
The renewal job may run on one machine while traffic has moved to another provider, CDN, or container.
A new subdomain, www redirect, or customer portal can be missed when the certificate is issued.
After renewal, test the public URL, not just the server file. The free checker shows the expiry date, issuer, domain coverage status, and a practical conclusion.
Run a public check after the renewal process reloads the website or proxy.
example.com and www.example.com can serve different certificates depending on your setup.
If the checker cannot confirm the certificate publicly, that is a customer risk worth investigating.
Cert Monitor is not a replacement for your renewal tool. It is an independent check from the outside, designed to tell you when the public website is close to expiry or cannot be confirmed.
The renewal tool changes the certificate; monitoring checks whether the customer-facing result is healthy.
A reminder gives you time to fix automation, DNS, or deployment issues before visitors are blocked.
Monitor the production domains, customer portals, and public admin endpoints where warnings would interrupt real users.
Renewal failures often show up as expiry, hostname mismatch, or a custom port serving an old certificate.
Check SSL expiry dates for public websites and start monitoring certificate expiration with email reminders before visitors see browser warnings.
Check whether an SSL certificate covers the exact public hostname, including www and subdomains, and monitor selected sites for future risk.
Check SSL/TLS certificates on public custom ports such as 8443 and start monitoring with email reminders for selected services.