Which of your certificates will 100-day lifetimes hit, and when?
Public TLS certificates drop to a 100-day maximum on 15 March 2027 and 47 days in 2029 (CA/Browser Forum SC-081). Enter a domain. You get every unexpired public certificate for it and its subdomains from Certificate Transparency logs, the ones that look renewed by hand, and their renewal dates under the new limits as a calendar file.
Your browser queries SSLMate's Cert Spotter API directly (crt.sh if it's busy). Nothing goes to us. Large domains take up to a minute.
Want alerts before each renewal, and help with the ones that can't use ACME?
We're building Cert Renewal Forecast: this inventory kept up to date from CT logs, email or Slack alerts before every manual renewal, and renewal agents for IIS, load balancers and firewalls. Alerts for up to 10 certificates will stay free. Join early access.
Had a certificate expire, or a renewal that took a weekend? Tell us what happened (4 questions, written, no call).
How it works, and what it can't see
- Source: every publicly trusted certificate is logged in Certificate Transparency. This page lists the unexpired ones whose names are your domain or its subdomains, grouped by name set (one row per certificate "slot", newest copy shown).
- Likely manual: lifetime over 100 days from a CA other than a cloud provider (e.g. DigiCert, Sectigo, GlobalSign, GoDaddy, Entrust). ACME clients almost always get ≤90-day certificates, so long-lived commercial ones are usually bought and installed by hand. This is a heuristic: CT logs show issuance, not how a certificate is installed. Some commercial CAs offer ACME with 200-day certificates.
- Cloud-managed: issued by Amazon, Google, Microsoft Azure, Cloudflare, Fastly or Akamai CAs, which their platforms renew for you.
- Renewal dates: renewing 14 days before each expiry, at the longest lifetime allowed on that day: 200 days until 14 March 2027, 100 days from 15 March 2027.
- Not covered: private/internal CAs, certificates on IP addresses, and anything not in CT logs. Names in CT logs are public by design; this page shows nothing that isn't already public.
Built by Hieu Tran with AI agents. Early and free; tell us where it's wrong. Schedule sources: CA/B Forum SC-081v3, Let's Encrypt, 7 Oct 2026. As of 10 Oct 2026.