NotAfter: TLS Monitor app icon

NotAfter: TLS Monitor

Not claimed

NotAfter shows you when TLS certificates expire – before a forgotten expiry date turns…

By Christian Bumberger · Utilities
Debuts score 78NewRate it first

Why we expect it: A carefully detailed tool that solves a real outage problem, with clear value for IT teams and admins.

NotAfter: TLS Monitor screenshot 1NotAfter: TLS Monitor screenshot 2NotAfter: TLS Monitor screenshot 3NotAfter: TLS Monitor screenshot 4

About

NotAfter shows you when TLS certificates expire – before a forgotten expiry date turns into an outage. Add your servers; the app reads the complete certificate chain, evaluates it and reminds you in time.

MONITOR • HTTPS and any TLS port (443, 8443, 636, 993, 995 …), optionally with its own SNI name for checks by IP address • STARTTLS: SMTP, IMAP, POP3, FTP and LDAP • RDP (Windows Remote Desktop, including NLA) • Certificate files (.cer, .crt, .pem, .pfx, .p12) for code signing, gateways or S/MIME • The whole chain: intermediate certificates expire too

EVALUATE • Days remaining per certificate, color coded • Warnings for hostname mismatch, self-signed certificates, missing intermediates, wrong chain order, SHA-1, RSA below 2048 bits and TLS 1.0/1.1 • Issuer, subject alternative names (SAN), key type and size, signature algorithm, TLS version • Internal certificates (e.g. from an Active Directory CA) are read anyway; import your own root CA and they count as trusted

REMIND • Local notifications before expiry, 30, 14, 7 and 1 day ahead by default, intervals and time of day are up to you • Checks at launch and occasionally in the background; when a certificate is renewed, NotAfter reschedules the reminders automatically • Widget with the next expiries for the Home and Lock Screen, badge on the app icon • Mac: menu bar item that re-checks every hour • Add an expiry to your calendar if you like • Webhooks report expiries, problems and renewals to Slack, Microsoft Teams, Discord or your own URL (JSON)

ORGANIZE • Groups bundle hosts, e.g. by customer or site; collapsible on iPhone • Mac: overview with key figures and an expiry chart, table with inspector, drag and drop for certificate files, CSV lists and addresses

DISCOVER • Network scan finds TLS services in an IPv4 range of your choice • Search the Certificate Transparency logs to see every publicly issued certificate of a domain and uncover forgotten hosts • Import host lists from CSV

REPORTS • CSV for Excel and PDF for audits or management

PRIVACY No account, no ads, no tracking. Hosts, settings and results stay on your device; optionally NotAfter syncs them with your other devices through your private iCloud. The domain search in the CT logs only sends the domain, when you start it, to crt.sh or Certspotter. Webhooks are off by default and only send to the URL you enter yourself.

Note: internal hosts can only be checked when the device can reach the host's network. The reminders still work because the expiry date is stored.

People rate it

Sign in to rate this app. Honest is what counts.

No ratings yet. Tried it? Be the first to rate it.

Discovery signals

How AI and people discover NotAfter: TLS Monitor on Debuts
AI-readyPartly
78% described for AI to match
Discoverable nowLiveStructured data on this page and the Debuts API

Tell us what you like. We only email when something new matches, and makers often add a deal for testers.

What kind of apps
On my
Only show me
How often
We send a link to confirm. Nothing arrives until you click it.