Skip to main content

Is Let's Encrypt Down?

No — Let's Encrypt is up

Reachable from all 8 checked regions

Average response time: 382ms

Last checked · checks run every 6 hours

Official status page: https://letsencrypt.status.io

Let's Encrypt uptime

Last 7 days
Last 30 days
Last 90 days
Avg response, 30 days

Measured from multiple regions every 6 hours. Percentages count only checks that returned an availability answer — 2 days measured so far. A dash means that window does not yet hold enough measured days to publish a figure.

30-day history

Jul 26: no data
Jul 27: no data
Jul 28: no data
Jul 29: no data
Jul 30: no data
Jul 31: no data
Aug 1: no data
Aug 2: no data
Aug 3: no data
Aug 4: no data
Aug 5: no data
Aug 6: no data
Aug 7: no data
Aug 8: no data
Aug 9: no data
Aug 10: no data
Aug 11: no data
Aug 12: no data
Aug 13: no data
Aug 14: no data
Aug 15: no data
Aug 16: no data
Aug 17: no data
Aug 18: no data
Aug 19: no data
Aug 20: no data
Aug 21: no data
Aug 22: 100.00% uptime, 24 checks
Aug 23: 100.00% uptime, 32 checks
Aug 24: no data
Jul 26 Today
No downtime Partial Downtime Not measurable No data

Reachability by region

Each region runs its own request from a different part of the world. A service can be up for one continent and down for another, which is usually the first sign of a routing or CDN problem.

cdg
71ms
DNS 0ms TCP 11ms TLS 16ms TTFB 39ms
dfw
202ms
DNS 0ms TCP 32ms TLS 38ms TTFB 106ms
ewr
57ms
DNS 0ms TCP 8ms TLS 13ms TTFB 35ms
fra
28ms
DNS 0ms TCP 2ms TLS 9ms TTFB 15ms
gru
28ms
DNS 0ms TCP 3ms TLS 10ms TTFB 18ms
iad
319ms
DNS 1ms TCP 3ms TLS 53ms TTFB 305ms
jnb
2082ms
DNS 0ms TCP 45ms TLS 353ms TTFB 1046ms
lax
250ms
DNS 0ms TCP 10ms TLS 17ms TTFB 152ms
lhr
95ms
DNS 0ms TCP 15ms TLS 20ms TTFB 52ms

What Let's Encrypt does

Let's Encrypt is a nonprofit certificate authority that issues free TLS certificates through the ACME protocol. Certbot and similar clients request and renew them automatically, without anyone buying a certificate by hand. Default certificates are valid for 90 days, with an opt-in six-day option, so renewal is a continuous background job rather than an annual purchase.

What an outage looks like

Existing sites keep serving HTTPS normally; what breaks is issuance. Renewal jobs fail with ACME errors against acme-v02.api.letsencrypt.org, new certificates cannot be obtained, and automated deployments that request a certificate on first boot stall. The visible damage arrives later, when a certificate that could not renew reaches its expiry and browsers start showing warnings.

What to do about it

Nothing urgent if your certificates are current: Let's Encrypt advises renewing at 60 days on a 90-day certificate, which leaves a month of slack for exactly this. Check letsencrypt.status.io, which lists the production and staging ACME endpoints separately from the website and the certificate transparency logs. Let the client retry on its own schedule rather than hammering the API.

Is it down for everyone, or just you?

If this page says Let's Encrypt is up but it is not loading for you, the problem is between you and them. Run a check against any URL from all 18 regions to find out where it breaks.

Test it yourself

Related services

Let's Encrypt outage FAQ

Will my HTTPS site break if Let's Encrypt is down?
No, not while your current certificate is valid. A certificate is a file your own server presents, and the browser verifies it against a root without contacting Let's Encrypt. An outage stops new issuance and renewal. The risk falls only on sites whose certificate expires during the window, which is why the recommended renewal at 60 days of 90 exists.
Does an outage affect revocation checking for visitors?
No. Let's Encrypt turned off its OCSP responder on August 6, 2025 and now publishes revocation information exclusively through Certificate Revocation Lists. That removed a live per-request dependency on Let's Encrypt from the browsing path, so a service incident today has no effect on visitors reaching sites that use its certificates.
My renewal failed once. Should I retry immediately?
No. Let's Encrypt asks that ACME clients renew at random times rather than in a synchronised rush, and repeated retries during an incident add to the load that is already the problem. Certbot and most clients back off on their own. With renewal at 60 days on a 90-day certificate, one failure has a month of headroom before it matters.
How do I tell a Let's Encrypt outage from a problem with my own setup?
Check the staging endpoint. letsencrypt.status.io lists acme-staging-v02 separately from production, and both are usually reported together during a real incident. If both are operational, the cause is more likely local: a firewall blocking the HTTP-01 challenge, a DNS record that has not propagated, or a rate limit your account has hit.

How we measure this

  • We request Let's Encrypt's public endpoint every 6 hours from Fly.io regions across six continents — 8 of them answered the most recent check.
  • A region counts as down only when it gets no usable HTTP response. A 403 or 429 means the origin answered and refused us, which we report as blocked, never as an outage.
  • A single failing region is treated as probe noise. We only change the verdict when two consecutive cycles agree.
  • Response times average only the regions that actually served the page, so a timeout never inflates the number.
  • Where Let's Encrypt publishes an official status feed we read it too. An all-clear from the vendor can soften an unconfirmed degradation; a vendor-declared outage only worsens our verdict when our own checks corroborate it.

Get alerted when Let's Encrypt goes down

This page refreshes every 6 hours. Your own monitors run as often as every 30 seconds, from the same 18 regions, and tell you the moment something breaks.

Start Free Monitoring
Free plan available No credit card required