Three failures need no attacker, no update and no bad luck, just time: the server stops answering, the certificate expires, the domain lapses. Each one is fully preventable with an alert someone set up on a bored afternoon.
This is that afternoon. Here is what each failure actually costs, the free alert setup, and the ownership audit that closes the loopholes alerts cannot.
The three timers
What each failure really costs
Downtime is the most forgiving. Google treats short outages as weather: it retries, and minutes-long incidents cost approximately nothing. The damage curve bends at days: extended 5xx responses reduce crawling, then rankings, and a week-long outage can take months to fully rebuild from.
SSL expiry is instant. The moment the certificate lapses, browsers replace your site with a security warning, and nearly everyone obeys the warning. Traffic does not decline; it stops, and every minute is customer-facing.
Domain expiry is the site-ender. Resolution stops, email stops, and a parking page often appears in your place while the registrar's grace-period meter runs. Renewal during grace usually works, sometimes with penalty fees; miss the whole window and you are bidding on your own name at auction.
| Failure | Visitor impact | SEO impact |
|---|---|---|
| Outage, under an hour | Some errors | Effectively none |
| Outage, days | Gone | Crawl reduction, then deranking |
| SSL expired | Scary warning, instant abandonment | Grows with duration |
| Domain lapsed | Parking page, dead email | Severe and compounding |
The alert setup
The Website Monitor from the Keywords Everywhere team covers all three timers free: uptime checks every 10 minutes, SSL expiry with days remaining, and domain expiry the same way, next to the SEO signal monitoring it also runs.
Two settings decide whether the alerts actually save you. Lead time: SSL warnings should land about two weeks out and domain warnings a good two months out, enough slack to fix payment or access problems, which are the real cause of most expiries. And recipients: alerts go to at least two humans, because single-inbox alerting fails on vacation, precisely on schedule.
The ownership audit
Expiries are rarely ignorance; they are orphaned ownership. Run this once.
Who can log into the registrar, and does anyone else have access if they vanish? Which card pays the renewal, and is it alive? Is auto-renew actually on, for the domain and every variant you own? Where is DNS hosted, and who can touch it? The classic disaster is a domain auto-renewing against a card that expired with the founder's old wallet, and the silent-break forensics afterward are no fun when the whole site is a parking page.
Multi-year renewals are the cheap insurance: registering the domain out five or ten years converts an annual roulette into a decade of not thinking about it.
When an alert fires
Downtime: confirm it is real from a second network, check your host's status page, and resist heroic restarts before understanding what is down. Most incidents are the host's and end themselves; your job is knowing, not fixing.
SSL: renew immediately, then automate so the category disappears; modern certificates renew themselves when someone sets it up once.
Domain: renew this minute, then do the ownership audit above, because a domain that got within alert-distance of expiry has an ownership problem, not a calendar problem.
The one-line takeaway: uptime, SSL and domain expiry are the three failures with known prevention: a 10-minute heartbeat, a 14-day certificate warning and a 60-day domain warning, sent to two humans, with auto-renew audited once. Boring by design; the alternative is a very exciting Tuesday.