Let’s Encrypt expiration emails: who owns certificate alerts?

Separate renewal jobs, deployment results and external TLS checks in certificate monitoring.

Contents of this article

Announcement and effective date

On January 22, 2025, Let’s Encrypt announced that expiration notification emails would end on June 4. The change concerned notifications, not ACME renewal or the validity of existing certificates.

A renewed certificate must also be deployed

Certificates may terminate at the CDN, load balancer and origin. Successful issuance only produces new files; a node may still serve the old certificate. Check TLS externally using the actual hostname rather than relying on local file dates.

Give alerts a second delivery path

Assign primary and escalation contacts for critical domains. Check alert delivery and clearly label production versus test certificates so routine noise does not hide an actual renewal problem.

Rehearse a renewal failure

Use a test domain to check permission failures, changed validation records and deployment errors. Verify that someone receives the alert, identifies the failing step and can restore service.

References

Let's Encrypt expiration email announcement

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support