SSL certificates expire every 90 days. The Plesk **SSL It!** extension can automatically renew certificates before they expire. This guide covers enabling and monitoring auto-renewal.

### Enabling Auto-Renewal

1. Log in to **Plesk**.
2. Go to **Websites & Domains** or **Domains**.
3. Click a domain → **SSL/TLS Certificates**.
4. Ensure the certificate is a **Let's Encrypt** certificate.
5. SSL It! automatically renews Let's Encrypt certificates **30 days** before expiry.

### Monitoring Certificate Expiry

1. Go to **Domains** and look for the SSL status indicator on each domain.
2. A warning icon indicates a certificate that is about to expire or has failed renewal.

### Important Notes

- Auto-renewal requires the SSL It! extension. Contact your hosting provider if it is not available.
- If a certificate fails to renew, check that the domain is still resolving to the server.

### Troubleshooting

**Auto-renewal failed:**

- Check that the domain DNS is still pointing to the server.
- Verify the domain has not exceeded Let's Encrypt rate limits.

### Related Guides

- [Provision certificates](/hc/help/en/articles/how-to-provision-ssl-certificates-for-plesk-customer-domains)
- [Check status](/hc/help/en/articles/how-to-check-ssl-status-across-plesk-domains)
- [Expiry dates](/hc/help/en/articles/how-to-view-ssl-certificate-expiry-dates-in-plesk)