DEV Community

ambolt
ambolt

Posted on Originally published at ambolt.dev

Check SSL certificates and domain expiry for a whole list of domains

An expired certificate or a lapsed domain takes a site down at the worst time, and it is almost always avoidable. If you look after more than a handful of domains, the useful question is not "what are the details for each?" but "which ones need attention this month?".

One request

curl "https://api.ambolt.dev/v1/domain-ssl-sweep?domain=sitemaps.org&warnDays=30&free=1"
Enter fullscreen mode Exit fullscreen mode

The answer has a summary and one result per domain:

{
  "checked": 1,
  "readable": 1,
  "flagged": 0,
  "warnDays": 30,
  "results": [
    {
      "domain": "sitemaps.org",
      "ok": true,
      "ssl": {
        "issuer": "Microsoft Corporation",
        "notAfter": "2026-12-07T04:56:13.000Z",
        "trusted": true,
        "daysLeft": 64,
        "expired": false
      },
      "registration": {
        "registered": true,
        "expiresAt": "2027-08-12T23:51:55Z",
        "daysToExpiry": 313,
        "registrar": "MarkMonitor Inc.",
        "nameservers": ["ns3-02.azure-dns.org", "ns1-02.azure-dns.com"]
      },
      "flags": []
    }
  ]
}
Enter fullscreen mode Exit fullscreen mode

Recorded 2026-10-03; fields trimmed. flags stays empty until something expires inside the window you set with warnDays, so a scheduled job only has to look at flagged and the flags.

A whole list

Pass domains with a list instead of domain, or run the Apify Actor on a schedule and send the flagged rows to your alerting. You are billed per domain checked; a domain that cannot be reached is listed with the reason and not charged.

What it does not return

Registrant details are never returned. SSL data comes from the certificate the server presents, and domain data from the registry's RDAP service, so a registry that does not publish an expiry date shows no date rather than a guess.

See the catalog for the tool and its price.

Top comments (0)