How to check SSL certificate expiration date before visitors see a warning

How to check SSL certificate expiration date before visitors see a warning

When a TLS certificate expires, browsers stop visitors at a warning page. Check the date it runs out, and whether the renewal will be allowed, while there is still time to fix it.

What happens when a certificate runs out

A TLS certificate is valid between two dates, not before and not after. Once the not-after date passes, browsers refuse the certificate and show a full-page warning in place of the site. Automatic renewal usually prevents that, but nothing tells you when it fails. A changed DNS record or a new certificate authority can stop it, and nobody notices until the old certificate ends.

Renewals now happen more often. Under CA/Browser Forum ballot SC-081, public certificates issued from 15 March 2026 can be valid for at most 200 days, and the limit keeps shrinking until it reaches 47 days in 2029. A second problem has nothing to do with dates: a certificate issued to other.example and served for example.com fails with a name mismatch even while it is in date.

Read the certificate, then the CAA policy

Enter the host name in the SSL Certificate Checker. It makes one TLS handshake to port 443 with that name for SNI, then shows whether the certificate verified, the subject and alternative names, the issuer, the key type, and the validity dates. Days remaining are counted from the not-after date. Under 30 days the row is marked as soon, and under 7 days as due. If verification fails, the certificate is still parsed and shown with the reason beside it, so you can read the names and dates of a broken one too.

Before the renewal date, look the domain up in the CAA Record Lookup. CAA records name the certificate authorities that may issue for a domain. The issue tag covers host names, issuewild covers wildcards, and iodef is an address for reports. An empty issue value means no CA may issue at all. If you moved to a CA that isn't listed, a CA that honors CAA will refuse the renewal. A domain with no CAA records isn't restricted by this policy.

Check when an SSL certificate expires

  1. Enter the host name in the SSL Certificate Checker, tick the robot check, and press Check.
  2. Confirm that it verified and that the alternative names include every name you serve, such as the www host.
  3. Read the not-after date and the days left.
  4. Enter the domain in the CAA Record Lookup and confirm your CA appears in an issue or issuewild row.
  5. Run the check again a few days after the renewal is due and confirm the new not-after date.

What these checks don't cover

  • The certificate check uses port 443 only. Mail ports and other TLS ports are out of scope.
  • One host per check. If both www and the bare domain serve the site, check each one.
  • A host that doesn't complete the handshake has no certificate to show. The page says the connection failed.
  • The CAA lookup shows the policy. It doesn't ask a CA what it would do, and it won't catch a CA that ignores CAA.
  • Neither tool watches a certificate over time. Each check is a single reading.

Frequently asked questions

How do I check when an SSL certificate expires?

Enter the host name in the SSL Certificate Checker. It shows the not-after date and the days left, and marks the row when fewer than 30 days remain.

How long is an SSL certificate valid?

Public certificates issued from 15 March 2026 can be valid for at most 200 days. The certificate example.com served on 3 October 2026 ran from 26 September to 25 December 2026.

Does a valid certificate mean the site is safe?

No. It means the name matches and a trusted issuer signed a certificate that is inside its dates. It says nothing about the page itself.

Can a CAA record block my certificate renewal?

Yes. If the domain publishes CAA records and your CA isn't in an issue or issuewild row, a CA that honors CAA will refuse to issue.

Tools used in this guide

  • SSL CertificateNetwork Tools

    Subject, alternative names, issuer, validity, and key type for the certificate on port 443.

  • CAA Record LookupDNS Tools

    CAA issue, issuewild, and iodef values, with a short note on each tag.

More from the blog

All guides