Bogus renewal notice?

I received an email from Let’s Encrypt Expiry Bot ( stating that a certificate on “” is set to expire on 19 September 2017. This is confusing to say the least as I do not have a subdomain “fred” on my server. As well, any certificates that I am using on are handled directly through my host, SiteGround–I have never logged into the Let’s Encrypt site and in fact had to create an account today in order to provide this support request.

Is there some phishing going on? Again, the source and purpose of the email sent by the Expiry Bot is very uncertain to me. Any help appreciated. Thanks very much.


Probably legit notice (but most likely for a cert that is no longer in use).
Can you share the details in the notice?

Well that was a fast reply :sunglasses:

here’s the notice in its entirety


Your certificate (or certificates) for the names listed below will expire in
19 days (on 19 Sep 17 18:09 +0000). Please make sure to renew
your certificate before then, or visitors to your website will encounter errors.

For any questions or support, please visit
Unfortunately, we can’t provide support by email.

For details about when we send these emails, please visit In particular, note
that this reminder email is still sent if you’ve obtained a slightly
different certificate by adding or removing names. If you’ve replaced
this certificate with a newer one that covers more or fewer names than
the list above, you may be able to ignore this message.

If you want to stop receiving all email from this address, click
(Warning: this is a one-click action that cannot be undone)

The Let’s Encrypt Team


again, thanks so much for your help


That is an accurate expiration for

Since the FQDN doesn’t resolve to any IP, I can only assume it is no longer in use.

Very good, thanks. I am new to your site (I typically handle LE certificates in SiteGround cPanel) so this was a nice bit of education. I am curious why the entry at

does not show up on

thanks again for your time

I suppose it has to do with “display limits”…
Can you imagine what a request on “” or “” would return if all related FQDNs were displayed?

OK cool, that makes sense…thanks so much again for your help here.

Indeed it is because it only searchs for exactly the domain name, if you want to search for certificates issued for you subdomains you need to use % as a wildcard



