The SSL warning threshold controls when a healthy certificate first changes to Warning. Choose 30, 14, or 7 days based on how your certificate is renewed and how much time your team needs to investigate.
Compare the options
| Threshold | Best fit | Tradeoff |
|---|---|---|
| 30 days | Manual renewals, several servers, change approval, or certificates managed by another team | Earliest notice and the most time to confirm every endpoint was updated |
| 14 days | Mostly automated renewal with a reasonable troubleshooting window | A balanced default when 30 days is earlier than your process needs |
| 7 days | Reliable automated renewal with active operational coverage | Less advance notice if automation or deployment fails |
The default is 30 days because it leaves the largest correction window.
Choose based on the entire renewal path
Consider more than the certificate authority's renewal date. A renewed certificate may still need to be deployed to:
- Load balancers and reverse proxies.
- CDN or edge endpoints.
- Multiple origin servers.
- Hosting control panels.
- Separate
wwwand non-wwwhostnames.
Choose enough time to renew, deploy, and verify the certificate actually presented to visitors.
How the threshold is evaluated
The daily check calculates whole days remaining from the public certificate's expiry timestamp. The state becomes Warning when the value is at or below your selected threshold.
Because the check runs approximately daily, the displayed value and warning time can differ slightly from a certificate tool that checks at another time of day.
What happens if you change the threshold
Open Expiry Monitoring, choose the new value, and select Save expiry monitoring. The next daily result evaluates the certificate using that threshold.
Moving from 7 days to 30 days can cause a certificate with 20 days remaining to enter Warning on the next check. Moving to a shorter threshold can return it to Healthy if it is outside the new warning period.
Notifications are state-change based. The same unchanged Warning is not sent every day.
Recommended starting point
Use 30 days unless you have a tested automatic-renewal process and a reason to shorten the window. After renewal, confirm the monitor reports the new date rather than assuming the certificate was deployed successfully.