Skip to main content

Choose SSL expiry warning thresholds

Compare the 30-day, 14-day, and 7-day certificate warning options and choose enough time for your renewal process.

The SSL warning threshold controls when a healthy certificate first changes to Warning. Choose 30, 14, or 7 days based on how your certificate is renewed and how much time your team needs to investigate.

Compare the options

Threshold Best fit Tradeoff
30 days Manual renewals, several servers, change approval, or certificates managed by another team Earliest notice and the most time to confirm every endpoint was updated
14 days Mostly automated renewal with a reasonable troubleshooting window A balanced default when 30 days is earlier than your process needs
7 days Reliable automated renewal with active operational coverage Less advance notice if automation or deployment fails

The default is 30 days because it leaves the largest correction window.

Choose based on the entire renewal path

Consider more than the certificate authority's renewal date. A renewed certificate may still need to be deployed to:

  • Load balancers and reverse proxies.
  • CDN or edge endpoints.
  • Multiple origin servers.
  • Hosting control panels.
  • Separate www and non-www hostnames.

Choose enough time to renew, deploy, and verify the certificate actually presented to visitors.

How the threshold is evaluated

The daily check calculates whole days remaining from the public certificate's expiry timestamp. The state becomes Warning when the value is at or below your selected threshold.

Because the check runs approximately daily, the displayed value and warning time can differ slightly from a certificate tool that checks at another time of day.

What happens if you change the threshold

Open Expiry Monitoring, choose the new value, and select Save expiry monitoring. The next daily result evaluates the certificate using that threshold.

Moving from 7 days to 30 days can cause a certificate with 20 days remaining to enter Warning on the next check. Moving to a shorter threshold can return it to Healthy if it is outside the new warning period.

Notifications are state-change based. The same unchanged Warning is not sent every day.

Recommended starting point

Use 30 days unless you have a tested automatic-renewal process and a reason to shorten the window. After renewal, confirm the monitor reports the new date rather than assuming the certificate was deployed successfully.

Related articles

Did this answer your question?

Your response helps improve this Help Center.