Reviewed September 2026

Red Sift Certificates Lite review: free, endorsed by Let's Encrypt, and hard to argue with

Most free tiers in monitoring are a demo with a paywall behind them. This one is not. Red Sift Certificates Lite monitors up to 250 certificates at no cost, finds them for you rather than making you type them in, and carries an endorsement from Let's Encrypt as its recommended expiration monitoring service. If your problem is purely certificates, you should look at this before you look at anything paid.

From $5 a month · No check quotas · Set up in under a minute

Is Red Sift Certificates Lite worth it?

It is free and it is good, so the question is really whether it is enough. For pure certificate expiry across a large estate, it is the strongest free option available and we would not pretend otherwise. Its limitation is the alert timing: notifications go out seven days before expiry, and that is a fixed figure. If your renewal process needs longer notice than a week, that single detail is what will send you elsewhere.

4.6/ 5
The best free certificate monitoring there is Our assessment, written by the team behind a competing product — read it as an informed opinion, not a neutral audit. Every factual claim is checked against Red Sift Certificates Lite's own public pricing and documentation at the time of writing.
Overview

What Red Sift Certificates Lite is

Red Sift Certificates Lite is a free certificate expiry monitor. You point it at your domains and it scans them daily over HTTPS on port 443, building an inventory of the endpoints it finds and the certificates installed on each one.

The discovery is the part that separates it from a simple checker. You are not maintaining a list by hand, which matters, because the certificate that takes a site down is almost always one nobody remembered was there.

In January 2025 Let's Encrypt named it their recommended certificate monitoring service. Given that Let's Encrypt issues more certificates than anyone and has a direct interest in subscribers not being caught out by expiry, that endorsement carries real weight.

Capabilities

What Certificates Lite does well

One job, done thoroughly, for nothing.

250 certificates, free

Not a trial and not a teaser. The allowance is large enough to cover a serious estate without ever reaching a payment page.

Automatic discovery

Daily HTTPS scans across your domains and subdomains find endpoints and their certificates, so forgotten hosts appear in the inventory instead of appearing in an outage.

A genuine inventory

You get visibility into which certificate is installed where, which is the part most expiry checkers skip entirely.

The Let's Encrypt endorsement

The recommended monitoring service of the largest CA in the world. That is not marketing; it is a signal about reliability from an organisation with no reason to flatter anyone.

No agent, no install

Everything is observed from outside over HTTPS, so there is nothing to deploy and nothing to maintain.

A path to more

If the estate outgrows it, the paid Certificates product adds cloud scanning, CT log analysis and CA integrations rather than making you migrate.

Cost

What Red Sift Certificates Lite costs

There is no pricing. That is the point of the product.

Plan Price Certificates Notes
Certificates Lite $0 Up to 250 No credit card. Daily scans, 7-day expiry alerts
Certificates Quote Enterprise scale Cloud scanning, CT log analysis, CA and registrar integrations

Monitoring vendors change plan limits and prices frequently and without announcement. Every figure here carries a "verify on their site" caveat and you should take it seriously before making a decision on cost.

The balance

Where it is strong, and where it is not

What works

  • Genuinely free for up to 250 certificates, with no credit card and no trial clock.
  • Discovers certificates automatically instead of relying on you to list them.
  • Recommended by Let's Encrypt as its certificate monitoring service.
  • Builds a real inventory of endpoints, not just a list of expiry dates.
  • Nothing to install and no agent to keep running.

What to watch out for

  • Expiry alerts are fixed at seven days, which is tight if renewals need approval or procurement.
  • Certificates only. No uptime checks, no domain expiry, no status pages.
  • Certificate Transparency analysis and cloud scanning are reserved for the paid product.
  • Scanning is over public HTTPS, so internal and private certificates are out of scope.
  • The free tier sits inside a much larger enterprise platform, which is more product than a small site needs.
Fit

Who Red Sift Certificates Lite is for

Choose it if

  • Anyone with a lot of certificates and no budget for monitoring them.
  • Teams who do not know how many certificates they actually have and want to find out.
  • Let's Encrypt users wanting a safety net behind their automation.
  • Security and infrastructure teams who need an inventory rather than a checklist.

Look elsewhere if

  • Anyone who needs more than a week of notice before a certificate expires.
  • People who want uptime, domain expiry and certificates answered by one tool.
  • Internal or private certificates that are not reachable over public HTTPS.
  • Teams wanting status pages or incident handling alongside.
Disclosure

Where MonitoringDaddy fits

On certificates alone, Certificates Lite beats us on two counts and we will not pretend it does not. It monitors 250 certificates for nothing, where our entry plan is $5 a month for 25 monitors of any type; and it discovers certificates for you, where we expect you to add each endpoint yourself.

Two things run the other way. Our expiry alert window is configurable from 1 to 60 days, against their fixed seven — and seven days is not much if a renewal has to go through someone else. We also alert when a certificate has already expired and when the certificate check itself fails, which is the state where a monitor has quietly stopped being a monitor. And the certificate is one of several things we watch in the same account: uptime, domain expiry from 1 to 180 days, page content changes, cron heartbeats and status pages.

The honest split: if certificates are the whole problem and 250 of them is the scale, use theirs and keep your $5. If the certificate is one of five things you would rather not find out about late, ours answers all five in one place.

See it

What an alert actually looks like

Every recorded change is compared word by word and kept with a before-and-after image. This is the real output, shown with worked example data.

competitor.com/pricing Watching: Pricing table
Pro plan — $49 per month
+ Pro plan — $39 per month
+ Save 20% with annual billing

Price fell from $49 to $39, and an annual discount was added.

2 words added · 1 removed · 4.1% of the watched region

retailer.com/product/… Watching: Availability
Out of stock
+ In stock — ships tomorrow
+ Add to basket

The item is available again and the basket button returned.

6 words added · 3 removed · 12.5% of the watched region

supplier.com/subprocessors Watching: Subprocessor list
~ Data is processed in the EUthe EU and the United States
+ Added: Northwind Analytics Inc. (United States)

A new subprocessor was added in another jurisdiction.

9 words added · 2 removed · 1.8% of the watched region

Worked example — not live data. Start monitoring free
Alerts

Where we can reach you

The free plan sends to one email address. Every paid plan adds the chat and webhook channels below, with 2 to 10 destinations depending on the plan. However many alerts you receive, the price does not change — nothing here is metered or charged per alert.

Email Before and after images inline
Browser push On a phone or desktop lock screen
RSS feed Every recorded change, as a feed
SlackPaid Through an incoming webhook
Microsoft TeamsPaid Through an incoming webhook
DiscordPaid Through an incoming webhook
TelegramPaid Straight to a chat or channel
FlockPaid Through an incoming webhook
WebhooksPaid Post to anything you run yourself

There are no voice calls and no SMS. If a phone call at 3am is a hard requirement, say so before you subscribe — we would rather tell you now than refund you later.

FAQ

Red Sift Certificates Lite review: your questions answered

Is Red Sift Certificates Lite really free?

Yes. Up to 250 certificates with no credit card required and no trial period. The paid Certificates product is a separate, enterprise-scale offering. Verify current limits on their site.

How far in advance does it warn you?

Seven days before expiry. That figure is fixed rather than configurable, which is the main practical limitation of the free tier.

Does it find certificates automatically?

Yes. It scans your domains daily over HTTPS on port 443 and builds an inventory of the endpoints it finds, so certificates you had forgotten about still get monitored.

Why does Let's Encrypt recommend it?

Let's Encrypt named it their recommended certificate monitoring service in January 2025. Their subscribers renew every 90 days, so a missed renewal is a realistic failure mode and an independent safety net behind the automation genuinely helps.

Does it monitor Certificate Transparency logs?

Not on the free tier. CT log analysis for detecting unauthorised certificates is part of the paid Certificates product. For CT monitoring specifically, SSLMate Cert Spotter is the dedicated tool.

Can it monitor internal certificates?

No. Scanning happens over public HTTPS, so anything not reachable from the internet is out of scope. TrackSSL offers private certificate monitoring on its higher plans.

Does it do uptime monitoring?

No. It is a certificate product. If you want certificates, uptime, domain expiry and page changes from one tool, that is a different category of product.

How does it compare with MonitoringDaddy?

For free certificate monitoring at scale with automatic discovery, theirs is better and we would say so. Ours is worth paying for when the certificate is one of several things you are watching, and when seven days of notice is not enough — our alert window runs from 1 to 60 days, and we also alert on certificates that have already expired.

Keep reading

Related reading

Last updated August 2026 · Written by Amit Gupta, founder of MonitoringDaddy

AG
Written by

Amit Gupta

Amit Gupta is the founder of MonitoringDaddy , a website and infrastructure monitoring platform built by TotosLocal One Private Limited. He writes about uptime, change detection, SSL and domain monitoring, and helps teams keep their websites fast, secure and online.

Certificates, uptime, domains and page changes in one account.

If certificates are all you need, Red Sift Lite is free and excellent. If they are one of several, start at $5 a month.