crt.watch
TLS and service monitoring

Watch certificates before customers notice problems.

crt.watch monitors certificates, TLS posture, DNS drift, STARTTLS services, logins, public status pages, and notifications from one self-hosted operator interface.

View on GitHub
All critical certificates coveredLive checks, expiry windows, TLS grading, DNS comparisons
OKmail.example.netTLS A, 62 days remaining
Warningapi.example.comCertificate changes watched
OKimap.example.orgSTARTTLS login succeeded
30 / 14 / 7expiry thresholds
SMTP, IMAP, POP3STARTTLS and SSL checks
Public pagescustomer-facing status
Prometheusmetrics for Grafana
Built for operators

Certificate monitoring plus the service checks around it.

The goal is a calm control room for certificate operations, not another noisy alert source.

Certificate intelligence

Expiry windows, SAN and hostname validation, issuer and fingerprint changes, chain checks, and TLS grading.

Protocol coverage

HTTPS, TCP TLS, SMTP, IMAP, POP3, FTP, SSH, DNS, login checks, and STARTTLS/SSL transport modes.

Quiet alerting

Notification routing, deduplication, recovery messages, escalation timing, quiet hours, and maintenance windows.

Change awareness

Certificate Transparency watch, DNS resolver comparison, SSL Labs assessments, and change notifications.

Self-hosted by default

Deploy it like infrastructure.

Run it with Docker Compose, keep data in a local bind mount, and update with your existing Watchtower flow.

curl -fsSL https://raw.githubusercontent.com/brightcolor/crt.watch/main/scripts/quickstart.sh | sudo bash