Origin Certificate Monitoring

Watch the SSL Cert Behind Cloudflare

When your site is behind a CDN, the padlock visitors see is Cloudflare's edge certificate — not the one on your real server. That origin certificate can expire silently. DomainCat watches it for you, and tells you honestly when it can't.

Start monitoring free

Free plan available · No credit card required

The Padlock You See Isn't the Whole Story

When a domain is proxied through Cloudflare, your visitors connect to Cloudflare — not directly to your server. So the SSL certificate their browser validates (the green padlock) is Cloudflare's edge certificate, which Cloudflare renews automatically. It basically always looks healthy.

Behind the CDN, your own server still presents its own certificate — the origin certificate. That's the one you actually manage, and the one that quietly expires at 2am while the browser padlock stays green. Most SSL checkers just load your site, see Cloudflare's cert, and report that everything is fine — right up until your origin cert lapses and things break in ways that are hard to diagnose.

DomainCat is built to close that blind spot. We detect when a domain is proxied, label the edge cert honestly, and monitor the origin certificate separately so an expiring origin cert can't slip past a healthy-looking edge.

How DomainCat Monitors Your Origin

Cloudflare hides your origin server on purpose, so we can't discover it from your domain name alone. You tell DomainCat where your origin is — its IP address or a direct, un-proxied hostname — and we connect to it directly while presenting your domain name (SNI), reading the certificate your server actually serves.

This works even on hardened origins that enforce Cloudflare Authenticated Origin Pulls: a server presents its certificate during the TLS handshake before it verifies any client certificate, so we can read the origin cert's issuer and expiry without bypassing your security. If your origin only accepts traffic from Cloudflare's IPs, you simply allowlist our prober — and DomainCat tells you exactly how when that's the case.

Honest Status — Never a False Green

If we can't actually see your origin cert, we say so plainly instead of showing a misleading checkmark. Every proxied domain shows one of these states:

MonitoredWe're watching the origin cert and will alert before it expires
Not setBehind a CDN — add your origin to turn monitoring on
UnreachableOrigin likely locked to Cloudflare — allowlist our prober IP
ConfirmWe found a likely origin — confirm it before we monitor a guess

The promise is simple: we won't let your certificate expire without you knowing. If there's something we genuinely can't see, we'd rather show you the gap — and how to close it — than pretend everything is green.

What You Get

🛡️
Edge + Origin, Side by Side
See both certificates for a proxied domain — Cloudflare's edge cert and your real origin cert — with their own issuers and expiry dates.
Origin Expiry Alerts
Escalating email alerts at 30, 14, and 7 days and on expiry — for the origin cert, not just the edge.
📡
Unreachable Detection
If a previously-watched origin goes dark, we alert you — a lost view of the origin is itself worth knowing about.
🔎
Origin Suggestions
DomainCat looks for un-proxied DNS records and suggests a likely origin — you confirm before we ever monitor it.
🟣
Honest CDN Labeling
Proxied domains are clearly marked so you always know whether you're looking at the edge cert or the origin cert.
🆓
On Every Plan
Origin certificate monitoring is available on the free plan too — not locked behind a paywall.

Built for Teams Running Sites Behind Cloudflare

If you or your clients front sites with Cloudflare (or another CDN), origin certificate monitoring closes a gap most tools miss entirely:

Related Monitoring Tools

DomainCat monitors more than the origin cert. Explore what else you can track:

See Behind Your CDN Today

Add a domain, point DomainCat at your origin, and start watching the certificate that actually breaks — automatically.

Get started free

Free plan · Up to 5 domains · No credit card required