Let's talk about your project
01 / Free tool

SSL certificate checker

An SSL (properly TLS) certificate encrypts the connection between the browser and your site and proves the site really belongs to you. A certificate that has expired, was issued for the wrong domain or has an incomplete chain shows a security warning in the visitor's browser and stops sales. This tool checks the certificate and connection settings in one go.

Only the server's public certificate and security header are read. To improve the tool and prevent abuse, the domain you check and the result are stored and deleted after 180 days.

Check your site's SSL certificate

  1. 01

    How to read the result

    Valid until and days left tell you when the certificate must be renewed. The names covered must include your site's exact name (with or without www). The chain shows whether browsers can verify the certificate up to a trusted root. The protocol should be TLS 1.2 or 1.3; HSTS tells browsers to always connect to the site encrypted.

  2. 02

    Certificate lifetimes are getting shorter

    Browsers and certificate authorities are gradually shortening the maximum certificate lifetime: at most 200 days from 15 March 2026, 100 days in 2027 and 47 days in 2029. Manual renewal is no longer sustainable; automatic renewal (e.g. ACME/Let's Encrypt or your host's automatic certificate) should be in place.

  3. 03

    The most common problems

    Forgetting renewal, a certificate issued for www that does not cover the bare domain (or the other way round), the intermediate certificate missing on the server (works in some browsers, fails in others) and old TLS versions left enabled. All of them show up as security warnings or reduce trust in search engines.

  4. 04

    What does this tool not check?

    The tool only checks the certificate and HTTPS settings at your site's main address. It does not check vulnerabilities inside the site, outdated software, admin panels or other subdomains; that needs an authorized security test.

06 / FAQ

Frequently asked questions

What the tool checks, what it cannot check and how to use the result.

My certificate is about to expire, what should I do?

Check in your host's panel that automatic renewal is enabled. If you bought the certificate manually, renew it, install it on the server and remember to add the intermediate certificate. Check again with this tool after renewing.

Is there a security difference between free and paid certificates?

Not in terms of encryption; free certificates such as Let's Encrypt provide the same encryption. Paid certificates may add organization validation, warranties or support.

What is HSTS and should I enable it?

HSTS is a header that tells browsers to connect to your site only over HTTPS for a period of time; it prevents unencrypted connections. It is recommended if all your subdomains serve HTTPS; try a short duration first, then extend it.

Does this check look like an attack on my site?

No. The tool opens a single normal HTTPS connection and reads the certificate and response headers; it sends or tries nothing on your site. It is the same as a visitor opening the site.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.