Articles · Infrastructure

2027-04-25 11 min EN / FR

DNS and SSL: the silent outages nobody monitors

Some of the most embarrassing outages have nothing to do with code. The site is down because a certificate expired at 3 a.m., a domain was not renewed because the reminder went to a former employee, or a DNS record was deleted during a cleanup. These failures are predictable, cheap to prevent and still extremely common, because nobody owns them.

Why they happen

  • Renewal is periodic and rare, so nobody remembers the procedure
  • The responsible person left, and reminders go to an address nobody reads
  • Accounts are in a contractor's name (see the 30-minute account audit)
  • Automation exists but broke silently, so nobody notices until the day it matters
  • Nothing is monitored, so the first alert is a customer

The four things that expire or break

1. Domain registration

When a domain expires, it typically goes through a grace period and then a redemption period, during which recovery can be possible but expensive and uncertain. After that, someone else can register it. The consequences include a dead website, dead email and possibly the loss of your brand name.

Protect it:

  • Registrant and registrar account in your company's name (see the account ownership audit)
  • Auto-renewal on, with a valid payment method and a card expiry reminder
  • Renewal reminders going to a role address read by several people
  • Two people able to log in, with 2FA that is not tied to a single phone
  • Registrar lock enabled, to prevent unauthorized transfers
  • Renewal dates in a shared calendar, with alerts a month and a week ahead
  • Consider multi-year renewal for critical domains

Renewals and payment methods belong in the same yearly hygiene as a solid maintenance contract.

2. SSL/TLS certificates

An expired certificate makes browsers show a full-page security warning, and API clients simply refuse to connect. Integrations, webhooks and mobile apps can fail without anyone seeing an error page.

Certificate lifetimes have been getting shorter across the industry, and more reductions are scheduled, so manual renewal is becoming impractical. Automate issuance and renewal, and monitor the result.

Protect it:

  • Use automatic renewal (for example via an ACME client, or your host's managed certificates)
  • Monitor expiry from the outside, with an alert at 30, 14 and 7 days. Do not trust that automation works. Verify it.
  • Keep a list of every certificate: main site, subdomains, API endpoints, mail servers, internal tools, VPN, wildcard certificates, third-party services using your domain
  • Make sure renewals still work after infrastructure changes (moved server, firewall rules blocking validation, DNS changes)
  • Check the full chain is served correctly, not just the main certificate
  • Document who gets the alert and what they do

Common causes of silent renewal failure: the validation challenge is blocked after a migration, a DNS provider changed and API credentials for DNS validation stopped working, a server was replaced and the renewal job did not follow, or a renewal runs but the web server is never reloaded to use the new certificate.

3. DNS records

DNS is a single point of failure that everything depends on.

Common incidents:

  • A record deleted during cleanup because nobody knew what it did
  • A change made without a record of what it was before
  • Dangling records pointing at services you no longer use (a security risk, since an attacker can sometimes claim the abandoned service and serve content on your subdomain)
  • Wrong TTLs making changes slow or reverts impossible
  • Single DNS provider with an outage
  • Email records broken after a change (see migrating DNS without breaking email)
  • DNSSEC misconfiguration after a provider change

Protect it:

  • Export the zone regularly and keep copies in version control or at least in a dated archive
  • Manage DNS with named access and an audit trail, limiting who can edit
  • Document each record and why it exists, before deleting anything
  • Review the zone once or twice a year for dangling and obsolete records
  • Use a provider with good availability, and consider a secondary DNS for critical domains
  • Make changes deliberately, with a rollback note

4. Everything that sits on top

Other things quietly expire or break:

  • Email authentication: SPF, DKIM and DMARC drift as tools are added (see DNS and email authentication)
  • API keys and OAuth tokens to third parties that expire or are revoked
  • Payment provider and integration credentials
  • Software licences and paid plugin subscriptions (see the account ownership audit)
  • Cloud accounts suspended because a payment card expired
  • Domain-verified services (analytics, search console, ad platforms) that lose verification when DNS changes

Add these to the same calendar and monitoring.

Domain or certificates on shaky ground?

We can map ownership, renewals and external checks so the next expiry is an alert, not a customer complaint.

A simple monitoring setup

You do not need an expensive platform. A reasonable minimum:

  • Uptime check on the website and key endpoints, from outside your network, checking for a valid HTTPS response, not just that something answers
  • Certificate expiry check for each public hostname, alerting well in advance
  • Domain expiry check, which many monitoring tools offer, or a simple scheduled script that reads the registration data
  • DNS record check: alert when key records (A, MX, TXT for SPF and DMARC) change unexpectedly
  • Email test: a periodic send-and-receive check through the real path
  • Alert routing to at least two people, through a channel that does not depend on the system being monitored (an email alert about a mail outage is useless if the mail is down)
  • A "no news" alarm for automated jobs: if the renewal job has not reported success recently, raise an alert (the same idea as watching sync jobs that go quiet in syncing two systems)

The yearly review: 30 minutes

Once a year, check:

  • List of all domains, with registrar, owner, expiry date and auto-renewal status
  • List of all certificates, expiry dates and how each is renewed
  • Export of the DNS zone, compared with the previous one
  • Obsolete and dangling records removed after verification
  • Renewal reminder addresses still valid and read
  • Payment methods on registrar, DNS, hosting and certificate accounts not about to expire
  • Two people can access each critical account (see the account audit)
  • Monitoring alerts tested, and recipients up to date

If it already broke

Domain expired:

  • Log in to the registrar at once. Renewal is often still possible during the grace period, possibly with an additional fee
  • If it is in redemption, contact the registrar for the restore procedure and cost
  • Check email and website after restoration, and re-verify any services that depend on the domain
  • Fix the cause before moving on: owner, reminders, payment, auto-renewal

Certificate expired:

  • Renew or reissue immediately
  • Install it and reload the service that serves it
  • Verify the full chain from outside and from a client that is not cached
  • Find out why automation or reminders failed, and add monitoring

DNS record deleted or changed:

  • Restore from your latest zone export, or from the provider's change history if it has one
  • Allow for TTL: some users will see the old state for a while
  • Check email records separately and test mail in both directions
  • Add an alert for changes to critical records

Common mistakes

  • Registrar account under a former employee or an agency
  • Reminders sent to someone who left
  • Auto-renewal on, with an expired card
  • Trusting automation without monitoring it
  • Certificates renewed on disk but never reloaded by the service
  • Deleting unknown DNS records
  • No backup of the DNS zone
  • One person holding all the access
  • Alerts routed through the system being monitored
  • Monitoring the website but not the API, subdomains or mail servers

Checklist

  • All domains in our name, auto-renewal on, registrar lock on
  • Reminders go to a shared role address
  • Two people can access registrar, DNS and certificate accounts
  • Certificates issued and renewed automatically, with external expiry monitoring
  • Inventory of certificates and subdomains
  • DNS zone exported regularly and changes documented
  • Dangling and obsolete records reviewed yearly
  • Uptime, certificate, domain and DNS change monitoring in place
  • Alerts routed to two people through an independent channel
  • Yearly 30-minute review in the calendar

Related

Want a second look at renewals and alerts?

Send your domain list and how certificates are issued today. We will flag what is unmonitored before the next expiry window.