The encrypt has announced that it will no longer inform users about the termination of adjacent certificate via email due to high cost, privacy concerns and unnecessary complications.
The decision to abolish the expiry notification email service was implemented by June 4, 2025, but the Encrypt has now communicated it through a blog post to raise awareness and prevent unexpected disruption.
The encrypt is an non -profit certificate authority (CA) that provides free, automatic and open digital certificate to enable HTTPS (SSL/TLS) on websites. In terms of size, they are among the largest causes in the world, issuing hundreds of crores of certificates to billions of websites.
Let’s encrypt is a transparent CA that has reduced data retention wherever possible. Its root certificate is included in all major browsers and OS Trust Stores, while it receives support from major technical firms such as Google, Cisco, Mozilla, EFF, Facebook and Akamai.
The organization uses an automated protocol called ACME (Automatic Certificate Management Environment), which enables websites and server software to automate, installation and renewal with minimal or no human intervention.
As Latest announcementThe existence of this automation is the primary reason that email notification service is getting sunset, as its need is decreasing.
The adoption of automatic renewal solutions has been further intensified by the changes of standards, such as the CA/Browser Forum recent announcement to reduce the certificate lifetime by 2029 to 47 days.
This decision made manual management impractical, if not impossible, firmly encourages the adoption of automation to remain obedient and avoid outage.
Another major reason for the decision to quit email service is the cost of running it, the estimates are estimated to be “tens of thousands of dollars per year”.
The organization believes that allocating this money to other aspects of its infrastructure would be more beneficial, which is unnecessarily stressful by handling email distribution activities.
“Providing expiration notifications adds complication to our infrastructure, which takes time and attention to manage and increase the possibility of mistakes,” said the Lats Encrypt.
“In the long term, especially when we add support to new service components, we need to stage the system components and manage overall complexity that can no longer be appropriate.”
Finally, the organization has user data privacy concerns, as now to maintain a large database of email address associated with the records issued to inform appropriate parties now is to maintain, manage and protect it.
Potentially affected users are the major takeaay to adopt the devices that support the ACME protocol if they do not already do so and stop relying on the notification email of the let’s encrypt.
If you need to receive renewal alert, consider installing external notification service in a different way.