Practical Guides 01 Sep 2026 7 min read

The deadlines an agency forgets (and they aren’t domains)

The deadlines an agency forgets (and they aren’t domains)

Everyone watches the domain. It’s the deadline that frightens people most, it has an obvious date, and when it fails even the client’s own customers notice. That’s precisely why it’s rarely the one that gets you into trouble.

The dangerous deadlines are the others: the ones that switch nothing visible off, that lapse in silence and get noticed weeks later, when the damage is already done. Below are the five that in our experience slip through most often, and what makes them different from a domain.

The SSL certificate

Let’s start with the objection: in most cases SSL renews itself, and putting it in a deadline tracker alongside the domain is a waste of time. True. The point is that when auto-renewal fails, it fails without telling anyone.

The cases where it breaks are always the same: a changed DNS record that breaks validation, a domain that expired in the meantime even for a few hours, a firewall or CDN rule blocking the check, a paid certificate not managed from the panel. The result is worse than a site being down: the site is there, but the browser puts a red warning screen in front of it. A visitor who sees that page doesn’t think “expired certificate”, they think “compromised site”.

Checking it properly means looking at the expiry date of the certificate the site actually serves, not the “active” status written in the hosting panel. Those are two different pieces of information more often than you’d expect.

Certified email and digital signatures

Here the trap is that there are two deadlines and they don’t coincide: the certified mailbox and the signature device. They renew separately, often with different suppliers and offset years, and whoever manages them tends to remember only one.

The consequences aren’t technical but legal. An expired certified mailbox stops receiving communications that carry legal weight, and the sender gets an error they’re unlikely to forward to you. The notices that were meant to land in that inbox simply don’t, and the fact that you never saw them doesn’t move any deadline. It has the worst ratio of visibility to potential damage of anything on this list.

It’s worth saying that often you don’t manage it: the accountant, or the client themselves, set it up. That’s not a good reason to leave it untracked. If the client sees you as the technical contact, when that mailbox stops working the first phone call comes to you anyway — and knowing immediately that it isn’t yours to fix, and who to pass it to, is already worth the minute it takes to write it down.

Software and plugin licences

When a licence expires the plugin almost always keeps working. That’s exactly what makes it insidious: nothing breaks, updates just stop arriving. The problem isn’t functional, it’s security, and it shows up months later as a known vulnerability left open.

There’s also a question to settle in advance, not afterwards: who pays for the licence, the agency or the client? If it’s in your name and the client leaves, the site is without updates from the day you deactivate it. If it’s in theirs, the renewal depends on someone who doesn’t know what they’re renewing. Both answers are fine, as long as one of them is written down.

Hosting and maintenance contracts

Hosting looks like the most closely watched deadline because the site goes down, but in practice it’s almost always on auto-renewal — and that moves it into the category of things nobody thinks about any more. Until the linked card expires: at that point every service with that supplier fails at once, silently, and the only warning is an email that looks like a thousand others.

The maintenance contract is the opposite case: it switches nothing off, so it either renews by inertia or doesn’t renew at all. If it has no tracked date, the moment you notice it lapsed is when you do work you assumed was covered — and at that point the conversation about the quote starts uphill.

It’s worth tracking two dates instead of one: the renewal date, and the date you want to raise it with the client, usually a month or two earlier. The first is for you, so you don’t find out late; the second is the only occasion when you can revisit the scope or the price without looking opportunistic.

Is a backup a deadline?

A backup has an expiry date, it’s called retention, and almost nobody treats it as one. If the plan keeps thirty days, the backup from thirty-one days ago no longer exists: retention expires exactly like a contract, only silently and every single day.

The practical problem is that the damage requiring a restore is often the kind discovered late — a corrupted table, a file deleted months earlier, overwritten content. By the time you go looking, the window has already closed.

And there’s the part almost nobody does: verifying that the restore works, not just that the backup exists. A backup that has never been tested is a hypothesis, not a guarantee. Putting it in the tracker as a recurring task, once a year, costs half an hour and changes the nature of the risk.

Which deadlines get forgotten most often?

  • Tracking only what switches the site off. The deadlines that break nothing are the ones you’ll discover late.
  • Trusting the “active” status in the panel. For SSL what counts is what the site actually serves, not what the interface says.
  • Treating certified email and digital signature as one thing. They’re two deadlines, with two suppliers and two dates.
  • Not deciding whose name the licences are in. The question always comes up, and it comes up at the worst moment.
  • Treating backups as a checkbox rather than a deadline. Retention burns down every day, and nobody warns you.

Where do you start listing your deadlines?

Inventory first, tool second. Adding these items to a tracker that doesn’t exist yet achieves nothing; adding them to one that already works is half a day.

  1. Make the list per client, not per type. For each one, ask what expires besides the domain: certificate, certified email, signature, licences, hosting, maintenance, backup retention.
  2. Note the supplier next to every item. On these deadlines the suppliers are more numerous and less familiar than the domain ones.
  3. Write down whose name it’s in. Who bought what: it’s the information that’s always missing when you need it.
  4. Separate automatic from manual renewals. The automatic ones shouldn’t be ignored, just checked differently: what you verify is the payment method.
  5. Add a recurring entry for the restore test. Once a year, per client or per group of clients.

If you don’t have a tracker yet, the starting point is how to organize a client deadline tracker for a web agency. If you’re wondering whether your spreadsheet holds up with these extra items, the answer is in managing deadlines in Excel: when it stops working. And on automatic client reminders, the logic is described on the notifications and emails page.


How do we track these deadlines ourselves?

From here on we’re talking about our own tool, so take it for what it is. Dotify was born at EnneStudio, our web agency in Padua, after a forgotten renewal cost us a client. The full story is on the about page.

On deadline types we made a choice that has everything to do with this article: alongside domain and hosting there are certified email, antispam and cloud, and types can be added. Not because another box was needed, but because the deadlines that actually slipped past us weren’t the domains.

There’s a free plan to try it. And if your conclusion is that you just need to add five rows to the spreadsheet you already use, that’s a perfectly valid conclusion: the value of this article is the list, not the tool.

Share this article:

Better manage your clients

Dotify automates deadlines, payments and communications. Free plan forever.