Setup

No agent to install. CertWatch checks your TLS endpoints and domains from CertWatch's own servers — you just tell it what to watch.

1. Create an account

Sign up at app.certwatch.sh/signup with an email and password. Every plan, including Free, starts immediately — no credit card required. Verify your notification email from the dashboard banner so alerts have somewhere to go; monitoring itself doesn't wait on that, but delivery does.

2. Add a TLS endpoint

From the Endpoints page, add a hostname and, optionally, a port (defaults to 443) and a label. This can be any TLS-speaking service — a website, an API, a mail server (e.g. port 993/995), or a database front door — not only HTTP servers. CertWatch dials it immediately to confirm the check works, then keeps it on your plan's check interval afterward.

Want to try it without an account first? The free certificate checker runs the same check CertWatch uses on a schedule, with no signup — useful for confirming a hostname resolves and presents a valid chain before you add it for ongoing monitoring.

3. Add a domain

From the Domains page, add a registrable domain name (e.g. example.com — no scheme, no port). CertWatch looks up its registration status via RDAP and tracks expiry, transfer lock, DNSSEC, and exposed registrant contact separately from any certificate served on that domain.

4. Configure alert delivery

Email is included on every plan. Pro accounts can add a Slack webhook or a generic webhook URL from Settings for alerts to go anywhere else you already page from. See Alerts for what actually triggers a notification.

5. Know your plan's limits

Each plan caps the number of endpoints and domains you can monitor and how often they're checked — see Billing for the current tiers. Hitting a limit while adding something new returns a clear "upgrade to continue" prompt rather than a silent failure.