TLS CERTIFICATE MONITOR FOR MACOS, WINDOWS & LINUX

Nobody notices a certificate until it expires on a Sunday.

Certificates are renewed by whoever set them up, remembered for about a year, and then forgotten — until the morning a browser puts a full-page warning in front of your customers. CertWatch keeps the list for you: it connects to the hosts you name, reads what they are actually serving, and tells you what expires when, what is no longer trusted, and what is quietly serving the wrong name. From your own computer. No agent on the server, no cloud account.

Expiry countdown Chain trust Hostname match Scheduled rechecks Local storage No cloud account

DEMO

See it in action

What it checks

For every host you add, CertWatch opens a TLS connection and reads the certificate the server actually presents — not what a database says it should be. It reports the days remaining, whether the chain is trusted, whether the name you asked for is really covered by the certificate, whether the signature algorithm is one that browsers still accept, and whether the host answered at all.

Each result gets a risk level, and the list sorts by it. The thing that will hurt you first is at the top.

Expired is not the only way to break

A certificate that is valid for another eight months can still be broken today. The intermediate was not installed, so it validates in your browser and fails in every command-line client. It covers example.com but the service moved to api.example.com. It was issued by an authority that has since been distrusted. CertWatch reports these the same way it reports expiry, because on the day they bite you they all look identical from the outside.

You do not have to remember to look

Free checks when you press the button. Pro rechecks on a schedule in the background and sends a webhook when something changes — to Slack, to Teams, to whatever receives JSON. A monitor you have to remember to open is a monitor that tells you after the fact.

Alerts are rate-limited, and a host that has been unreachable for three days does not send three days of alerts.

Whole subnets, not one host at a time

Pro takes a CIDR range and finds what is listening on the TLS ports inside it. Most people discover this way that there are more certificates on their network than they thought — the appliance web interface, the printer, the management port on the switch, the staging box someone stood up in 2023 and never took down.

It watches DNS too PRO

A certificate is only half of what makes a name work. CertWatch tracks the DNS records behind the hosts you monitor and tells you when one changes — because a certificate that is perfectly valid on a server the name no longer points at is not doing anything for you.

Something to hand to an auditor

Export the whole inventory as CSV, or produce a PDF report: every host, issuer, expiry date, risk level and when it was last checked. It is the answer to "show me your certificate inventory" that does not involve a spreadsheet somebody maintains by hand.

Everything stays on your computer

The host list, the results and the licence key live in a folder in your home directory. CertWatch connects to the hosts you added and to nothing else — no telemetry, and no licensing callback, because the licence key is verified locally against a public key built into the app. It works on a network with no route to the internet, monitoring internal hosts a hosted checker could never reach.

It fits with the rest

CertWatch registers itself with the other MeshWatch apps on the same computer, so a device you are already watching elsewhere can be opened here without retyping its name.

DOWNLOAD

Get CertWatch

Notarised · Version 0.4.5 · Apple silicon

macOS

macOS 12 Monterey or newer, Apple silicon. Signed with an Apple Developer ID and notarised by Apple, so it opens without a Gatekeeper warning. Intel build coming later.

Download DMG · 115 MB

Signed · Version 0.4.5

Windows — 64-bit

Windows 10/11 and Windows Server 2016 or newer (Desktop Experience). Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.

Download Installer · 99 MB

Version 0.4.5

Linux — 64-bit

Ubuntu 22.04 or newer, Debian 12 or newer. The .deb declares its dependencies, so it installs and runs on a minimal server install with nothing added by hand. Verified on Ubuntu 24.04, Ubuntu 22.04 and Debian 12.

Verify your download

Run shasum -a 256 CertWatch-0.4.5-arm64.dmg in Terminal and compare the result with the published checksum.

Checksums

Installation and administration guide → — first run, settings, firewall rules, and connecting it to MeshWatch Central.

Every install starts with a 30-day trial of Pro. Nothing is asked for up front — no card, no account, no email address.

PRICING

Free for a handful of hosts. Pro when the list grows.

Free

$0

Enough for a personal domain and a side project.

  • Up to 3 hosts shown
  • Expiry, trust and hostname checks
  • Weak signature detection
  • Risk-sorted results
  • Manual rechecks
Download

Pro

$99/year

For the person who gets the call when a certificate expires.

  • Everything in Free
  • Unlimited hosts
  • Scheduled background rechecks
  • Webhook alerts (Slack, Teams, custom)
  • Subnet scanning by CIDR
  • DNS change monitoring
  • Audit CSV and PDF reports
  • Priority support
Buy CertWatch Pro

Or start the 30-day trial first — no card, no account.

Free limits what is shown, never what is checked: hosts beyond the third are still scanned and still stored, they are just hidden until you upgrade — a monitor that silently skips hosts while looking like it is working would be the worst thing this could be. Pro is activated with a licence key emailed after checkout; the key carries its own expiry and is verified on your own computer, so CertWatch never contacts a licensing server. When a subscription lapses the free features continue.

FAQ

Common questions

How is this different from a free online SSL checker?

An online checker tests one host, once, from the public internet, when you remember to go there. CertWatch keeps the list, rechecks it on a schedule, tells you when something changes, and can reach hosts that are not on the public internet at all — the appliance on your management VLAN, the internal API, the staging box behind the VPN. If you have three public domains and a good memory, the free checkers are genuinely fine.

Does it need anything installed on my servers?

No. It connects the way any client would, reads the certificate the server presents, and disconnects. Nothing is installed on the host, and no credentials are needed — a TLS certificate is public by design.

Can it renew certificates for me?

No, and that is deliberate. Renewal means holding credentials for your certificate authority and your DNS provider, and writing files onto production servers. CertWatch is a monitor: it tells you what needs attention and leaves the doing to you and to whatever already issues your certificates.

What does "untrusted" actually mean?

That the chain the server presented could not be validated against the system trust store. Usually a missing intermediate certificate — the leaf is fine, but the server was configured without the rest of the chain, so browsers that have cached the intermediate succeed and everything else fails. It can also mean a self-signed certificate, or an authority that has since been distrusted. CertWatch says which.

How does subnet scanning behave?

It walks the range you give it with a limit on how many connections run at once, so it does not look like a port scan to your own network gear and does not saturate a link. Hosts that do not answer on a TLS port are simply not listed.

Where do alerts go?

To a webhook URL you provide. Slack and Microsoft Teams incoming webhooks are supported directly; anything else receives a JSON body you can shape to your own endpoint. There is no MeshWatch relay in the middle — the request goes from your computer to your endpoint.

Does anything leave my computer?

Only the TLS connections to the hosts you added, the DNS lookups behind them, and alert webhooks if you configure one. The host list and results are stored in your home directory. There is no telemetry and no licensing callback.

How does Pro activation work?

After checkout you receive a licence key by email. It is sent from license@meshwatch.app, usually within a minute — if it is not in your inbox, check your Junk or Spam folder before writing to support. Paste it into the app and Pro unlocks on that computer. The key carries its own expiry date and is checked locally against a public key built into the app, so activation works offline. When you renew, a fresh key is emailed to you.

Does it work with MeshWatch Central?

Optionally. Connect CertWatch to your own MeshWatch Central server and its alerts join whatever ConfigWatch, DeviceWatch, TrafficWatch, SyslogWatch and TrapWatch are reporting into one shared inbox — a certificate expiring on the same host ConfigWatch just saw change shows up as one incident, not two unrelated alerts in two unrelated apps. CertWatch sends Central a one-line summary like “certificate expires in 4 days” — never the certificate itself, never a private key. Central is a separate product you run on your own server; CertWatch works exactly the same with or without it.

CONTACT

Questions or feedback? Email support@meshwatch.app or open a topic on the Support page.