25 September 2026 · One command a day
How do I test that certbot can renew my SSL certificate?
certbot renew --dry-run checks that every Let's Encrypt certificate on your server could be renewed right now, without renewing anything. It runs the full renewal process against the Let's Encrypt staging server and throws the result away. You reach for it after changing nginx, DNS or the firewall, and whenever you want proof that automatic renewal will work before a certificate is close to expiry.
The command
sudo certbot renew --dry-run
sudo is needed because certbot reads and writes under /etc/letsencrypt, which belongs to root. certbot renew goes through every certificate certbot manages and renews the ones due within 30 days. --dry-run changes two things. It talks to the staging server rather than the production one, so nothing counts against your rate limits and no real certificate is issued. It also attempts every certificate, not just the ones that are due, so you get a complete answer in one go.
What you will see
Saving debug log to /var/log/letsencrypt/letsencrypt.log
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/example.com.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Account registered.
Simulating renewal of an existing certificate for example.com and www.example.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations, all simulated renewals succeeded:
/etc/letsencrypt/live/example.com/fullchain.pem (success)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
One block appears per certificate. The summary at the end is the part to read. Each line marked (success) is a certificate that will renew without trouble. If one fails, the summary lists it under a failure heading and the block above explains why. The usual causes are a challenge that could not be reached over port 80 or a domain that no longer points at this server. The Account registered. line is normal the first time, because the staging server keeps a separate account.
When to use it
- After changing your nginx config, moving a site or adding a redirect, because renewal relies on the
/.well-known/acme-challenge/path still being served over plain HTTP. - After tightening a firewall or moving to a new IP address, to confirm Let's Encrypt can still reach the server.
- Right after setting up a new server, before you rely on the certbot timer to renew everything on its own.
Watch out for
A dry run is not free of side effects. Any --pre-hook or --post-hook stored in the renewal config still runs, so a hook that stops nginx will stop nginx. Only deploy hooks are skipped. If you use the standalone authenticator, certbot also needs port 80 free, and the dry run fails if something else is listening there. You can find out what that is with the command in How do I see which process is using a port on Linux?.
Questions people ask
Does a dry run change my real certificate?
No. The test certificate is never saved to disk and your existing certificate is untouched. Only the renewal config and the staging account files may be updated.
How do I check when the real certificate expires?
Run sudo certbot certificates to list every certificate with its expiry date, or check from outside with the command in How do I check a website's SSL certificate from the command line?.
Testing renewal before it matters is only possible where you hold root on the machine that owns the certificates. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.
Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.
Affiliate link.