Domain expiry
On Cloud, a scheduled job looks up domain assets through RDAP (IANA bootstrap, cached 24 hours; IDN converted to ASCII) and writes a new expires_at when the registry expiration event differs. Lookup failure never clears an existing date. A change is logged as whois.updated.
This is RDAP, not classic WHOIS. It does not cover every TLD, does not guarantee a date, and does not show registrar contacts or unpublished renewals. Self-hosted does not run this job.
Versus SSL check
SSL check connects to port 443 and reads the certificate. It needs no registrar account and does not inspect domain registration expiry.