The Padlock You See Isn't the Whole Story
When a domain is proxied through Cloudflare, your visitors connect to Cloudflare — not directly to your server. So the SSL certificate their browser validates (the green padlock) is Cloudflare's edge certificate, which Cloudflare renews automatically. It basically always looks healthy.
Behind the CDN, your own server still presents its own certificate — the origin certificate. That's the one you actually manage, and the one that quietly expires at 2am while the browser padlock stays green. Most SSL checkers just load your site, see Cloudflare's cert, and report that everything is fine — right up until your origin cert lapses and things break in ways that are hard to diagnose.
DomainCat is built to close that blind spot. We detect when a domain is proxied, label the edge cert honestly, and monitor the origin certificate separately so an expiring origin cert can't slip past a healthy-looking edge.
How DomainCat Monitors Your Origin
Cloudflare hides your origin server on purpose, so we can't discover it from your domain name alone. You tell DomainCat where your origin is — its IP address or a direct, un-proxied hostname — and we connect to it directly while presenting your domain name (SNI), reading the certificate your server actually serves.
This works even on hardened origins that enforce Cloudflare Authenticated Origin Pulls: a server presents its certificate during the TLS handshake before it verifies any client certificate, so we can read the origin cert's issuer and expiry without bypassing your security. If your origin only accepts traffic from Cloudflare's IPs, you simply allowlist our prober — and DomainCat tells you exactly how when that's the case.
Honest Status — Never a False Green
If we can't actually see your origin cert, we say so plainly instead of showing a misleading checkmark. Every proxied domain shows one of these states:
The promise is simple: we won't let your certificate expire without you knowing. If there's something we genuinely can't see, we'd rather show you the gap — and how to close it — than pretend everything is green.
What You Get
Built for Teams Running Sites Behind Cloudflare
If you or your clients front sites with Cloudflare (or another CDN), origin certificate monitoring closes a gap most tools miss entirely:
- Works with Cloudflare-proxied domains, including Authenticated Origin Pulls
- Watches the origin cert separately from the edge cert — two certs, both visible
- Tells you exactly how to fix an unreachable origin (allowlist the prober IP)
- Never reports a false "healthy" when it can't actually see the origin
- Set the origin IP or hostname when you add a domain, or any time after
- Available on Free, Pro, and MSP — no paywall on the core feature
Related Monitoring Tools
DomainCat monitors more than the origin cert. Explore what else you can track: