Most free tiers in monitoring are a demo with a paywall behind them. This one is not. Red Sift Certificates Lite monitors up to 250 certificates at no cost, finds them for you rather than making you type them in, and carries an endorsement from Let's Encrypt as its recommended expiration monitoring service. If your problem is purely certificates, you should look at this before you look at anything paid.
From $5 a month · No check quotas · Set up in under a minute
Is Red Sift Certificates Lite worth it?
It is free and it is good, so the question is really whether it is enough. For pure certificate expiry across a large estate, it is the strongest free option available and we would not pretend otherwise. Its limitation is the alert timing: notifications go out seven days before expiry, and that is a fixed figure. If your renewal process needs longer notice than a week, that single detail is what will send you elsewhere.
Red Sift Certificates Lite is a free certificate expiry monitor. You point it at your domains and it scans them daily over HTTPS on port 443, building an inventory of the endpoints it finds and the certificates installed on each one.
The discovery is the part that separates it from a simple checker. You are not maintaining a list by hand, which matters, because the certificate that takes a site down is almost always one nobody remembered was there.
In January 2025 Let's Encrypt named it their recommended certificate monitoring service. Given that Let's Encrypt issues more certificates than anyone and has a direct interest in subscribers not being caught out by expiry, that endorsement carries real weight.
One job, done thoroughly, for nothing.
Not a trial and not a teaser. The allowance is large enough to cover a serious estate without ever reaching a payment page.
Daily HTTPS scans across your domains and subdomains find endpoints and their certificates, so forgotten hosts appear in the inventory instead of appearing in an outage.
You get visibility into which certificate is installed where, which is the part most expiry checkers skip entirely.
The recommended monitoring service of the largest CA in the world. That is not marketing; it is a signal about reliability from an organisation with no reason to flatter anyone.
Everything is observed from outside over HTTPS, so there is nothing to deploy and nothing to maintain.
If the estate outgrows it, the paid Certificates product adds cloud scanning, CT log analysis and CA integrations rather than making you migrate.
There is no pricing. That is the point of the product.
| Plan | Price | Certificates | Notes |
|---|---|---|---|
| Certificates Lite | $0 | Up to 250 | No credit card. Daily scans, 7-day expiry alerts |
| Certificates | Quote | Enterprise scale | Cloud scanning, CT log analysis, CA and registrar integrations |
Monitoring vendors change plan limits and prices frequently and without announcement. Every figure here carries a "verify on their site" caveat and you should take it seriously before making a decision on cost.
On certificates alone, Certificates Lite beats us on two counts and we will not pretend it does not. It monitors 250 certificates for nothing, where our entry plan is $5 a month for 25 monitors of any type; and it discovers certificates for you, where we expect you to add each endpoint yourself.
Two things run the other way. Our expiry alert window is configurable from 1 to 60 days, against their fixed seven — and seven days is not much if a renewal has to go through someone else. We also alert when a certificate has already expired and when the certificate check itself fails, which is the state where a monitor has quietly stopped being a monitor. And the certificate is one of several things we watch in the same account: uptime, domain expiry from 1 to 180 days, page content changes, cron heartbeats and status pages.
The honest split: if certificates are the whole problem and 250 of them is the scale, use theirs and keep your $5. If the certificate is one of five things you would rather not find out about late, ours answers all five in one place.
Every recorded change is compared word by word and kept with a before-and-after image. This is the real output, shown with worked example data.
Price fell from $49 to $39, and an annual discount was added.
The item is available again and the basket button returned.
A new subprocessor was added in another jurisdiction.
The free plan sends to one email address. Every paid plan adds the chat and webhook channels below, with 2 to 10 destinations depending on the plan. However many alerts you receive, the price does not change — nothing here is metered or charged per alert.
There are no voice calls and no SMS. If a phone call at 3am is a hard requirement, say so before you subscribe — we would rather tell you now than refund you later.
Yes. Up to 250 certificates with no credit card required and no trial period. The paid Certificates product is a separate, enterprise-scale offering. Verify current limits on their site.
Seven days before expiry. That figure is fixed rather than configurable, which is the main practical limitation of the free tier.
Yes. It scans your domains daily over HTTPS on port 443 and builds an inventory of the endpoints it finds, so certificates you had forgotten about still get monitored.
Let's Encrypt named it their recommended certificate monitoring service in January 2025. Their subscribers renew every 90 days, so a missed renewal is a realistic failure mode and an independent safety net behind the automation genuinely helps.
Not on the free tier. CT log analysis for detecting unauthorised certificates is part of the paid Certificates product. For CT monitoring specifically, SSLMate Cert Spotter is the dedicated tool.
No. Scanning happens over public HTTPS, so anything not reachable from the internet is out of scope. TrackSSL offers private certificate monitoring on its higher plans.
No. It is a certificate product. If you want certificates, uptime, domain expiry and page changes from one tool, that is a different category of product.
For free certificate monitoring at scale with automatic discovery, theirs is better and we would say so. Ours is worth paying for when the certificate is one of several things you are watching, and when seven days of notice is not enough — our alert window runs from 1 to 60 days, and we also alert on certificates that have already expired.
Last updated August 2026 · Written by Amit Gupta, founder of MonitoringDaddy
If certificates are all you need, Red Sift Lite is free and excellent. If they are one of several, start at $5 a month.