🔐 Domain, SSL & DNS Monitor - Expiry + Change Alerts avatar

🔐 Domain, SSL & DNS Monitor - Expiry + Change Alerts

Pricing

Pay per event

Go to Apify Store
🔐 Domain, SSL & DNS Monitor - Expiry + Change Alerts

🔐 Domain, SSL & DNS Monitor - Expiry + Change Alerts

⚡ Never lose a domain or serve an expired certificate again. ✅ Domain expiry via RDAP, live TLS certificate expiry and validity, nameserver and DNS record changes. ✅ Warns before expiry and alerts the moment records move. No API key needed.

Pricing

Pay per event

Rating

0.0

(0)

Developer

mohamed alaya

mohamed alaya

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

7 days ago

Last modified

Share

Domain, SSL & DNS Monitor

Three of the most expensive outages in tech are also the most preventable: a domain that quietly expired, a certificate nobody renewed, and DNS records that changed without anyone noticing. This watches all three.

What it checks

Domain (via RDAP, the structured successor to WHOIS) — registrar, registration status, DNSSEC, nameservers, and daysUntilDomainExpiry.

TLS certificate (read live off the socket, not from a third party) — issuer, subject, SAN list, fingerprint, daysUntilCertExpiry, and whether it actually validates.

DNS (over DNS-over-HTTPS) — A, AAAA, MX, NS, TXT and more, snapshotted and compared.

What raises an alert

  • Domain or certificate inside your warning window (expiryWarningDays, certWarningDays)
  • A certificate that no longer validates
  • Nameservers changed — often the first visible sign of a domain hijack
  • Certificate issuer changed, or registration status changed
  • Any watched DNS record changing

What deliberately does not alarm you

A rotated certificate fingerprint is reported but is not treated as critical on its own — Let's Encrypt renews every 60 days and flagging that as an incident would train you to ignore the alerts. A changed issuer is critical; a routine renewal is not.

DNS answers and nameserver lists are sorted before comparison, so a round-robin resolver returning the same records in a different order can never look like a change.

Typical uses

Agencies and MSPs watching client domains · security teams tracking hijack indicators · DevOps preventing certificate outages · anyone who has ever lost a domain to auto-renew failing silently.

Schedule it

Daily is right for expiry and DNS. Point webhookUrl at Slack and you will hear about a problem weeks before it becomes an outage.