# SSL & Domain Expiry Checker — Bulk Renewals · $0.005/domain (`ambolt/domain-ssl-sweep`) Actor

Check SSL certificate and domain registration expiry for a list of domains in one run. Returns issuer, validity dates, days left, trust status, registrar and nameservers, and flags everything expiring inside your warning window. Run it on a schedule for renewal alerts. Failed domains are free.

- **URL**: https://apify.com/ambolt/domain-ssl-sweep.md
- **Developed by:** [Ambolt](https://apify.com/ambolt) (community)
- **Categories:** AI, Agents, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$5.00 / 1,000 domains

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## SSL & Domain Expiry Checker — Bulk Renewals · $0.005/domain

Check SSL certificate and domain registration expiry for a list of domains in one run. Returns issuer, validity dates, days left, trust status, registrar and nameservers, and flags everything expiring inside your warning window. Run it on a schedule for renewal alerts. Failed domains are free.

Check SSL certificate and domain registration expiry for one domain or a whole list: certificate issuer, valid from and to, days left, trusted or not, domain registration and expiry dates, registrar and nameservers. Flags what expires within your warning window. Registrant details are never returned.

### What you get

Structured JSON for each run, ready for spreadsheets, alerts and AI agents. Also available as an MCP tool (`domain_ssl_sweep`) and as a pay-per-call HTTP endpoint.

### Input

| Field | Type | Default | Description |
|---|---|---|---|
| `domain` | string |  | One domain, for example example.com. Use this or domains. |
| `domains` | array |  | Up to 100 domains in one run (Apify Actor only). Each domain that returns a result is one billable result. |
| `warnDays` | integer | 30 | Flag certificates and registrations that expire within this many days. |
| `checks` | string (both, ssl, domain) | both | Which checks to run for each domain. |

### Example input

```json
{
  "domain": "www.sitemaps.org",
  "warnDays": 30
}
```

### Example output

```json
{
  "checked": 1,
  "readable": 1,
  "flagged": 0,
  "warnDays": 30,
  "billableResults": 1,
  "checkedAt": "2026-10-03T14:58:44.626Z",
  "note": "SSL data comes from the certificate the server presents; domain data from the registry RDAP service. Subdomains share their parent domain registration.",
  "results": [
    {
      "domain": "www.sitemaps.org",
      "ok": true,
      "ssl": {
        "subject": "www.sitemaps.org",
        "issuer": "Microsoft Corporation",
        "notBefore": "2026-08-29T12:16:28.000Z",
        "notAfter": "2026-12-07T11:16:28.000Z",
        "sans": [
          "www.sitemaps.org"
        ],
        "protocol": "TLSv1.3",
        "trusted": true,
        "trustError": null,
        "daysLeft": 64,
        "expired": false
      },
      "registration": {
        "registered": true,
        "registeredAt": "2001-08-12T23:51:55.459Z",
        "expiresAt": "2027-08-12T23:51:55Z",
        "daysToExpiry": 313,
        "registrar": "MarkMonitor Inc.",
        "nameservers": [
          "ns3-02.azure-dns.org",
          "ns1-02.azure-dns.com",
          "ns2-02.azure-dns.net",
          "ns4-02.azure-dns.info"
        ],
        "status": [
          "client delete prohibited",
          "client transfer prohibited",
          "client update prohibited"
        ]
      },
      "flags": []
    }
  ]
}
```

### Pricing

| Event | Price |
|---|---|
| domain (each successful result) | $0.005 |

**Failed runs are not charged.** Free trial credits from Apify cover your first runs.

### FAQ

**Is a result guaranteed to be complete?** Each result carries the date it was read. If the upstream service is down the run fails with a clear message and you are not charged.

**Can I call it from code or an AI agent?** Yes: run it through the Apify API, or use the MCP tool and pay-per-call endpoint listed at https://ambolt.dev.

**Is this affiliated with the data source?** No. Source names are used descriptively; each result keeps its source attribution and licence line.

**Where do I report a problem?** Open an issue on this Actor's page; replies are written by the Ambolt service team, usually within a day.

### Review

If this Actor saved you time, a short review on its Store page helps others find it and tells us what to improve.

### Keywords

SSL expiry, certificate expiry, domain expiry, bulk domain check, renewal reminder, TLS certificate checker, domain monitoring, agency

### Notes

Data comes from the source named in each result and keeps its licence and attribution. Informational only, not financial, legal or tax advice. Open an issue on the Actor page for questions; replies come under the product name.

# Actor input Schema

## `domain` (type: `string`):

One domain, for example example.com. Use this or domains.

## `domains` (type: `array`):

Up to 100 domains in one run (Apify Actor only). Each domain that returns a result is one billable result.

## `warnDays` (type: `integer`):

Flag certificates and registrations that expire within this many days.

## `checks` (type: `string`):

Which checks to run for each domain.

## Actor input object example

```json
{
  "domain": "www.sitemaps.org",
  "warnDays": 30,
  "checks": "both"
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domain": "www.sitemaps.org",
    "warnDays": 30
};

// Run the Actor and wait for it to finish
const run = await client.actor("ambolt/domain-ssl-sweep").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "domain": "www.sitemaps.org",
    "warnDays": 30,
}

# Run the Actor and wait for it to finish
run = client.actor("ambolt/domain-ssl-sweep").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domain": "www.sitemaps.org",
  "warnDays": 30
}' |
apify call ambolt/domain-ssl-sweep --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,ambolt/domain-ssl-sweep"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/MBt7aFDhg4XNrrsMj/builds/uCAaif0LksOu0PWtd/openapi.json
