Why the expiry date is the number that matters
A certificate does not degrade. It is completely valid, and then at a precise timestamp it is completely invalid, and every browser in the world switches to a blocking warning at once. There is no grace period and no partial failure to warn you first.
That makes the days-remaining number the only useful metric. Knowing a certificate is “valid” tells you nothing — it was valid the day before it expired too. Knowing it has four days left tells you what to do this afternoon.
Why manual tracking always fails eventually
The usual system is a spreadsheet of renewal dates, and it works right up to the point where it doesn’t. Certificates get reissued early and the new date never makes it into the sheet. A site moves behind Cloudflare and starts presenting a different certificate on a different schedule. Someone leaves and the column stops being updated.
Ninety-day certificates make it worse, not better. Auto-renewal removes the deadline from anyone’s calendar entirely, so when the renewal silently breaks there is no longer a human anywhere in the loop who expects to hear about it.
Auto-renewal removed the deadline from everyone’s calendar. When the renewal hook silently breaks, there is no longer a human in the loop who expects to hear about it.
How Zeqo Watch works for you
This page answers the question for one host, right now. It performs a real handshake and reports the certificate’s `notAfter` date with the days remaining.
Zeqo Watch does it every day for every domain you add, and tells you when a certificate crosses into the warning window — with enough notice to fix a broken renewal hook rather than scramble for an emergency reissue.
Add the client sites once, and expiry stops being something anyone has to remember.
