List the addresses and assign an owner
A business website may use more addresses than its homepage: the main domain, its www version, and a separate booking or ordering application. Start with a short inventory of the addresses customers and staff use. For each one, record where it is hosted, who manages its certificate and who receives alerts.
SSL is a common label for the certificates used to serve HTTPS over TLS. In day-to-day operations, the relevant details are the specific name covered and the actual expiry date. Request those details for each service; checking the homepage does not automatically cover every application your business uses.
Verify that automatic renewal works
Issuing the first certificate and renewing it later are separate steps. Ask the administrator to identify the scheduled renewal task, its last run and any recorded errors. A successful task run does not necessarily mean a new certificate was issued: renewal may not have been due yet.
For installations using Certbot, the official documentation provides a renewal test. The administrator should first review the configuration and associated actions, because a test may temporarily affect the web server. Record the outcome and repeat the check after a material infrastructure change.
Understand how domain control is validated
With Let's Encrypt HTTP-01 validation, the check starts on port 80 and requests a specific file under /.well-known/acme-challenge/. A new firewall or access rule can block that path even while the homepage continues working over HTTPS.
DNS-01 validation uses a specific TXT record. Recheck this process after changing DNS providers or revoking the automation's permissions. DNS credentials should have only the permissions needed for the task. The administrator should confirm the appropriate validation method for the particular environment.
Include certificates in every DNS change
Moving hosting, replacing nameservers or adding a CDN is a useful trigger for another check. Assign someone to verify issuance and renewal after the change and retain the result. This gives the work a completion criterion beyond the correct page appearing in a browser.
Review any CAA records as well. These specify which certificate authorities may issue certificates for the domain. A policy that excludes the authority being used can prevent new issuance. Removing every restriction is not the default fix; the administrator should align the policy with the intended issuance process.
Check the certificate actually being served
A new file on the server does not prove that the service is already using it. After renewal, check the website's exact hostname, expiry date and certificate chain validity from an external network. Where several systems serve HTTPS, verification should cover each relevant endpoint.
With a CDN or reverse proxy, there may be two TLS connections: visitor to intermediary, and intermediary to origin server. The certificate shown by the browser belongs to the first connection. Request separate verification of the second where it is used, without bypassing validation simply to make an error disappear.
Make sure an alert reaches a responsible person
Combine renewal checks with independent monitoring of expiry and failed connections. Assign an alert owner and a replacement for absences. Choose a response window appropriate to the certificate lifetime and renewal cycle, instead of applying the same threshold to every service.
Do not rely exclusively on a reminder from the certificate authority. Let's Encrypt has discontinued its certificate expiration notification email service. Confirm that your own monitoring has an active recipient and that a warning leads to an assigned task, a recorded outcome and a follow-up check.
Close the check with a concrete result
Send the hosting administrator a short list of addresses and the questions below. Record the check date and a next step for outstanding items. For a FastVPS service, confirm the management scope of the particular package and responsibility for any external DNS or CDN.
- Which addresses were checked, and when does each certificate expire?
- Which automation performs renewal, and who verifies its outcome?
- Was the certificate currently in use verified externally?
- Who receives alerts, and which changes require another check?
Sources & further reading
- Let's Encrypt: Challenge Types
- Certbot: User Guide — Renewing certificates
- Let's Encrypt: Certificate Authority Authorization (CAA)
- Cloudflare: Full (strict) TLS encryption
- Let's Encrypt: Expiration Notification Service Has Ended
- FastVPS: Web hosting
Prepared with AI assistance and checked against the sources above. Service scope is confirmed in your FastVPS order.