Never lose a domain or a certificate to a missed renewal
Registration and certificate expiry are tracked with separate warning and critical windows, so a lapse is a scheduled task weeks in advance instead of an outage nobody could have predicted.
Watch registration expiry, WHOIS and nameserver changes, DNSSEC, certificate replacement, Certificate Transparency, SPF, DKIM, DMARC and blacklists on one domain.
Registration and certificate expiry are tracked with separate warning and critical windows, so a lapse is a scheduled task weeks in advance instead of an outage nobody could have predicted.
Nameserver, A and AAAA, MX and CAA records are compared against a recorded baseline. A change opens a finding with the previous and current values side by side, and alerts once rather than on every check.
A new fingerprint at renewal is normal. A changed issuer, key algorithm or removed subject name is not, and neither is a certificate appearing in a public Certificate Transparency log that you did not request.
SPF records are checked against the ten-lookup limit that silently stops them applying, DKIM selectors for revoked and undersized keys, and DMARC for a policy or coverage quietly weakened during debugging.
When a data source cannot be reached, the check reads as unverified rather than passing. A registry that publishes no expiry date says so, and a list that needs a key says which key, instead of showing a green tick nobody should trust.