Feature

SSL, domain & security

The outages you can see coming weeks ahead — an expiring certificate, a domain nobody renewed — and the headers that decide how exposed the site is in between.

What it does

Certificates and domains fail on a calendar, not at random, which makes them the one class of downtime that is entirely preventable. zutpralik reads the expiry date of both and warns you days in advance, while there is still time for somebody to act.

The certificate check goes past the expiry date to the chain itself: an intermediate that is missing or out of order will break some clients while looking perfectly fine in your own browser.

Alongside that runs a security-headers audit — HSTS, CSP, X-Frame-Options and the rest — so you can hand a client a concrete list of what is missing instead of a vague recommendation to “improve security”.

  • SSL certificate expiry, with alerts days before the date
  • Full certificate-chain validation, not just the leaf
  • Domain (WHOIS) expiry tracking
  • Security-headers audit: HSTS, CSP, X-Frame-Options and others
  • Email authentication: SPF, DKIM and DMARC records checked

FAQ

About ssl, domain & security

How far in advance am I warned about an expiring certificate?

Days ahead, not hours — the point is to leave room for whoever has to renew it. The window is part of the check configuration rather than something fixed.

Why check the chain if the certificate is valid?

Because a missing or misordered intermediate is invisible in a desktop browser that has cached it, and fatal to mobile clients and API consumers that have not.

Does the headers audit change anything on my site?

No. It reads the response headers and reports what is present or missing. Nothing is modified on the monitored site — zutpralik only ever looks.