# Received email about certificate expiration

**URL:** <https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169>\
**Category:** Help\
**Created:** [November 23, 2021, 1:28pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169 "2021-11-23T13:28:01Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rogier](https://avatars.discourse-cdn.com/v4/letter/r/ecc23a/32.png) [@rogier](https://community.letsencrypt.org/u/rogier)\
**Post date:** [November 23, 2021, 1:28pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/1 "2021-11-23T13:28:01Z")

</div>

I received the email below. I lists my domain names.  
But I don't think the email is correct. F.e. one of the domain names is liefseva.nl. When I check the certificate myself, then I see that it does not expire tomorrow (see screenshot below).

So what is wrong? I never received these emails from let's encrypt before.

> Hello,
> 
> Your certificate (or certificates) for the names listed below will expire in 0 days (on 24 Nov 21 05:43 +0000). Please make sure to renew your certificate before then, or visitors to your web site will encounter errors.
> 
> We recommend renewing certificates automatically when they have a third of their total lifetime left. For Let's Encrypt's current 90-day certificates, that means renewing 30 days before expiration. See [Integration Guide - Let's Encrypt](https://letsencrypt.org/docs/integration-guide/) for details.

 ![Screenshot 2021-11-23 at 15.01.52](https://global.discourse-cdn.com/letsencrypt/original/3X/7/d/7d2328bc8170062f237ff17ae2236710217aaaf5.png)

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [November 23, 2021, 2:30pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/2 "2021-11-23T14:30:26Z")

</div>

Your [certificate history](https://crt.sh/?q=liefseva.nl) shows that you used to have one certificate that covered both `liefseva.nl` and `www.liefseva.nl`, but now have two separate certificates from Let's Encrypt, one for each of the names. Also, you now have certificates from ZeroSSL, and your screenshot above shows that that's the one you're actually using.

So, that's why you got the email: Your certificate covering both names is expiring, and (as the email says in it, after the portion you quoted) if you add or remove names that's a "different" certificate so you're getting expiration notices for the old one. If you're confident that your server is now sending the right certificates, then the reminder can be safely ignored. It is a little weird to be using both ZeroSSL _and_ Let's Encrypt, though, so you may want to ensure that your systems are doing what you expect.

Some other resources that might help:

> [@Received Expiration Email But Already Renewed Certificate: What to Know and Do](https://community.letsencrypt.org/t/received-expiration-email-but-already-renewed-certificate-what-to-know-and-do/151785):
>
> I…

> **[Expiration Emails - Let's Encrypt](https://letsencrypt.org/docs/expiration-emails/)**
>
> Subscribing If you provide an email address to Let’s Encrypt when you create your account, we’ll do our best to automatically send you expiry notices when your certificate is coming up for renewal. We try to send the first notice at 20...

---

<div class="post-metadata">

**Author:** ![rogier](https://avatars.discourse-cdn.com/v4/letter/r/ecc23a/32.png) [@rogier](https://community.letsencrypt.org/u/rogier)\
**Post date:** [November 23, 2021, 2:58pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/3 "2021-11-23T14:58:02Z")

</div>

Ah! Well then caddy and traefik both implement different ways-of-working here. Because I recently switched from Traefik to Caddy as my reverse proxy.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 23, 2021, 2:59pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/4 "2021-11-23T14:59:05Z")

</div>

Furthermore, even if the names are exactly the same: If the CA has been changed (from LE to ZeroSSL) then you will be receiving emails from LE for all the LE certs as those begin to expire.

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/9/3/939a2e64357a348aa0100b5a2129e32b4627fa74.png)

> [@rogier](#):
>
> then caddy and traefik both implement different ways-of-working here

Probably just that all new `acme.sh` installs now default to `ZeroSSL`.  
[that can be set to use LE if you like]

---

<div class="post-metadata">

**Author:** ![rogier](https://avatars.discourse-cdn.com/v4/letter/r/ecc23a/32.png) [@rogier](https://community.letsencrypt.org/u/rogier)\
**Post date:** [November 23, 2021, 3:10pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/5 "2021-11-23T15:10:49Z")

</div>

Maybe a stupid question, but which one is better? (just home-server user here)

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [November 23, 2021, 3:24pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/6 "2021-11-23T15:24:28Z")

</div>

Well, "better" based on what criteria? They're both equally trusted in major browsers and such. Let's Encrypt is [run by a non-profit](https://www.abetterinternet.org/about/), whereas ZeroSSL isn't and is probably hoping that you end up eventually using one of their paid offerings. Let's Encrypt is primarily a service targeted at automated systems directly (by which I mean, the only access is through the ACME API and there's no web interface or built-in monitoring or whatnot, with the only support being this community forum), whereas ZeroSSL is designed to be a bit more user-friendly for people looking for a more traditional CA experience (meaning that they have a web console and offer more direct support & sales offerings). But I wouldn't say any one of those is _inherently_ better than the other (though others here might).

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [November 23, 2021, 3:36pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/7 "2021-11-23T15:36:21Z")

</div>

> [@rogier](#):
>
> which one is better?

If you are only serving new(er) clients then I'd say both are equally trusted and would work equally.  
If you have a very wide range of clients (new, old, and very old), then you might want to use ZeroSSL.  
[which could be simpler to deal with such a scenario (for the time being)]

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [November 23, 2021, 3:48pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/8 "2021-11-23T15:48:50Z")

</div>

As an aside, the website [help.zerossl.com](http://help.zerossl.com) uses certificates from Let's Encrypt (I kid not)

```nohighlight
Certificate chain
 0 s:/CN=help.invoicely.com
   i:/C=US/O=Let's Encrypt/CN=R3
 1 s:/C=US/O=Let's Encrypt/CN=R3
   i:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
 2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1
   i:/O=Digital Signature Trust Co./CN=DST Root CA X3

SANs:
help.eversign.com
help.invoicely.com
help.zerossl.com

```

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 23, 2021, 3:49pm UTC](https://community.letsencrypt.org/t/received-email-about-certificate-expiration/166169/9 "2021-12-23T15:49:42Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
