Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

25 September 2026 · One command a day

How do I test that certbot can renew my SSL certificate?

certbot renew --dry-run checks that every Let's Encrypt certificate on your server could be renewed right now, without renewing anything. It runs the full renewal process against the Let's Encrypt staging server and throws the result away. You reach for it after changing nginx, DNS or the firewall, and whenever you want proof that automatic renewal will work before a certificate is close to expiry.

The command

sudo certbot renew --dry-run

sudo is needed because certbot reads and writes under /etc/letsencrypt, which belongs to root. certbot renew goes through every certificate certbot manages and renews the ones due within 30 days. --dry-run changes two things. It talks to the staging server rather than the production one, so nothing counts against your rate limits and no real certificate is issued. It also attempts every certificate, not just the ones that are due, so you get a complete answer in one go.

What you will see

Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/example.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Account registered.
Simulating renewal of an existing certificate for example.com and www.example.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/example.com/fullchain.pem (success)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

One block appears per certificate. The summary at the end is the part to read. Each line marked (success) is a certificate that will renew without trouble. If one fails, the summary lists it under a failure heading and the block above explains why. The usual causes are a challenge that could not be reached over port 80 or a domain that no longer points at this server. The Account registered. line is normal the first time, because the staging server keeps a separate account.

When to use it

Watch out for

A dry run is not free of side effects. Any --pre-hook or --post-hook stored in the renewal config still runs, so a hook that stops nginx will stop nginx. Only deploy hooks are skipped. If you use the standalone authenticator, certbot also needs port 80 free, and the dry run fails if something else is listening there. You can find out what that is with the command in How do I see which process is using a port on Linux?.

Questions people ask

Does a dry run change my real certificate?

No. The test certificate is never saved to disk and your existing certificate is untouched. Only the renewal config and the staging account files may be updated.

How do I check when the real certificate expires?

Run sudo certbot certificates to list every certificate with its expiry date, or check from outside with the command in How do I check a website's SSL certificate from the command line?.

Testing renewal before it matters is only possible where you hold root on the machine that owns the certificates. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: How do I check a website's SSL certificate from the command line? · How do I query a specific DNS server with dig? · How do I check what a domain resolves to from the command line?