In short: An expired security certificate or a lapsed domain name can take your whole site offline in an instant, often without warning. Maintena watches both for you around the clock and gives you plenty of notice before anything runs out, so you are never caught out.
What it is
Two of the quietest, most damaging things that can happen to a website are an expired security certificate and a lapsed domain name. Either one can knock your site offline, show visitors a scary browser warning, or hand your web address to someone else. They rarely give a warning, and they always seem to happen at the worst moment.
Maintena removes that risk. We check two things for you on a schedule:
- Your security certificate (SSL). This is the padlock that lets visitors connect to your site securely and shows "https" in the address bar. We record whether it is valid, who issued it, when it was issued, and, most importantly, how many days are left before it expires.
- Your domain name. This is your web address itself. We check its registration and renewal dates, its DNS settings (the records that point your address at your site and your email), and a few basic security and email-authentication signals.
You do not need to do anything special to set this up beyond having a site in Maintena. Everything runs in the background, and the results appear on your site's SSL & Domain page.
How it works
We reach out to your site and to public domain registries directly. Nothing here depends on the WordPress agent being installed, so these checks keep working even if the agent is offline.
What we check, and how often
Certificates can change at any time, so we look at them frequently. Domain registration changes very slowly, so we check it once a day.
| What we watch | How often | What we look at |
|---|---|---|
| Security certificate (SSL) | Every 6 hours | Validity, issuer, issue and expiry dates, days until expiry, and basic strength signals |
| Domain name | Once a day | Registrar, registration and expiry dates, DNS records, nameservers, and email-authentication settings |
When you first add a site, we run both checks straight away, so your SSL & Domain page fills in within seconds rather than waiting for the next scheduled run. You can also trigger a fresh check any time with the Recheck now button on the page.
The certificate details we surface
Beyond "is it about to expire", we translate the technical detail into plain checks you can read at a glance. Where the information is available, the page shows things like:
| Check | What it means for you |
|---|---|
| Not self-signed | Your certificate was issued by a recognised authority, not made up on the server |
| No weak SHA-1 | It uses modern, secure signing rather than an outdated method |
| Strong key | The certificate uses a robust encryption key size |
| HTTPS enforced | Visitors who type "http" are sent to the secure version automatically |
| HSTS enabled | Browsers are told to always use the secure connection in future |
Each check comes with a short, plain-English description so you always know what it is telling you.
The domain details we surface
For your domain we show who it is registered with, the key dates, the nameservers in use, and your DNS records (the A, MX, TXT and similar entries that route your website and email). We also check a few security signals:
| Check | What it means for you |
|---|---|
| SPF | An email-authentication record that helps stop others sending spam as you |
| DMARC | A stronger email-authentication policy that protects your domain's reputation |
| DNSSEC | Extra protection that stops your domain records being tampered with |
| Registry lock | A protective lock at the registry that guards against unauthorised transfers |
A history you can see
Every check is saved, so your page shows more than just today's snapshot. You get expiry trend lines and a short event timeline that flags meaningful changes, such as a certificate being renewed, a domain being renewed, or your DNS records changing. We keep certificate history for around 90 days and domain history for around a year.
How we warn you
This is the part that matters most. As an expiry date approaches, we email the account's main contact so you have time to act. We send one email per stage, not a daily stream of reminders.
| We email you when there are this many days left | |
|---|---|
| Security certificate (SSL) | 30, 14, 7, 3, and 1 day |
| Domain name | 60, 30, 14, 7, and 1 day |
We start warning about domains earlier because registrars usually want renewals sorted well in advance.
Once the certificate or domain is renewed, the reminders reset automatically. If a future expiry ever creeps up again, you will be warned again from the top. Warnings go to your account's main contact email address.
It feeds your Health Score
Your certificate is one of the ingredients in your site's daily Health Score, contributing a portion of the overall number based on whether it is valid and how close it is to expiry. A healthy, comfortably-in-date certificate helps keep your score high. Domain information is shown for your awareness but does not currently affect the score.
What you need to do
For most customers the honest answer is: nothing. It works out of the box. To get the full value, just make sure of the following.
- Have the monitors switched on. Domain monitoring is on by default for new sites, and certificate monitoring is set when the site is added. If either is off and you would like it on, your Success Manager can enable it.
- Make sure your account has a contact email. Expiry warnings go to your account's main contact address, so keep it current. If it is missing, we simply record the check quietly and update the page without emailing.
- Act on a warning when it arrives. Maintena tells you in good time, but it does not renew anything for you. When you get a reminder, renew your certificate or domain with your provider, or ask your Success Manager for a hand.
That is all. Your existing site address is everything the checks need.
Good to know
- We report, we do not renew. Maintena is your early-warning system. It will never buy, transfer, or auto-renew a certificate or domain on your behalf, so the decision always stays with you.
- The page is never blank. If we cannot reach your certificate, we record that clearly instead of showing an error. If a domain's registry does not publish full details (which happens with some country domains), we still show your DNS records, nameservers and email-authentication settings, and mark the registration details as unavailable.
- How we judge a certificate. Our "valid" verdict is based on the certificate matching your site's address and still being within its valid date range. We also flag self-signed and outdated-signing certificates separately as extra safeguards. We do not currently perform full trust-chain, revocation, or certificate-transparency checks.
- One recipient today. Expiry warnings go to your account's single main contact. There is no additional CC, Slack, or webhook option at the moment.
- No extra cost or setup. These checks use free, public data sources and your own site, so there is nothing extra to configure. For what is included in your plan, see Billing & Subscriptions.
On the roadmap
A few enhancements are noted for the future and are not available today:
- Deeper certificate verification, including full trust-chain, revocation, and certificate-transparency checks.
- Domain health in the score, so your domain's status could influence your Health Score the way your certificate already does.
- More flexible alerts, such as choosing your own warning thresholds and sending to more than one recipient.