SSL & security monitoring for agencies: never miss a client's expired cert
If you build and maintain websites for clients, you already know the worst call to get: "our site is showing a security warning and customers are leaving." Nine times out of ten it's a certificate that expired without anyone noticing. When you manage ten, thirty, fifty client sites, checking each one by hand is impossible — so it doesn't get checked, until a browser does it for you in front of your client.
Why "auto-renew handles it" isn't true often enough
Let's Encrypt and most hosts auto-renew certificates, and most of the time it works. But renewals fail silently more often than teams expect:
- A renewal cron job breaks after a server migration and nobody notices.
- DNS validation fails because a record was moved during an unrelated change.
- A site is rebuilt on a new stack and the old renewal setup is left behind.
- A rate limit or an expired API token quietly blocks the renewal.
The common thread: the failure is invisible until the certificate actually expires. That gap — between "renewal failed" and "certificate expired" — is where monitoring saves you. A monitor sees the certificate is 14, then 7, then 3 days from expiry and tells you, so you fix a cron job on a quiet afternoon instead of firefighting during business hours.
Certificates aren't the only thing that drifts
Two other things silently regress across client sites, and both show up when a client's customer runs a security review on them:
- Security headers. A redeploy or a new CDN config drops HSTS or a Content-Security-Policy that used to be there. The site still works, so nobody notices — until a pentest flags it. See the security headers guide.
- DNS & email authentication. An SPF or DMARC record gets edited during an email migration and email starts landing in spam or spoofing protection quietly weakens.
What agency-grade monitoring looks like
You don't need an enterprise platform. You need one place that watches every client domain and only interrupts you when something's actually wrong:
| The manual way | Monitored |
|---|---|
| Remember to spot-check sites (you won't). | Every domain re-checked automatically, every day. |
| Find out when the client calls. | Email alert the moment a cert nears expiry or a header regresses. |
| Log into each host to check. | One dashboard, every client site, at a glance. |
That's exactly what Perimeter's Agency plan is for: watch up to 25 client domains, get a daily check and an instant alert on any regression, and one weekly digest across everything — for a flat $29/month, no per-site pricing and no sales call.
Check a client site right now — free
Run any domain through the same engine that powers the monitoring. TLS, security headers and DNS, graded in seconds. No signup.
See the Agency plan → · watch up to 25 domains for $29/mo