SSL CertificateNetwork Tools
Subject, alternative names, issuer, validity, and key type for the certificate on port 443.
When a TLS certificate expires, browsers stop visitors at a warning page. Check the date it runs out, and whether the renewal will be allowed, while there is still time to fix it.
A TLS certificate is valid between two dates, not before and not after. Once the not-after date passes, browsers refuse the certificate and show a full-page warning in place of the site. Automatic renewal usually prevents that, but nothing tells you when it fails. A changed DNS record or a new certificate authority can stop it, and nobody notices until the old certificate ends.
Renewals now happen more often. Under CA/Browser Forum ballot SC-081, public certificates issued from 15 March 2026 can be valid for at most 200 days, and the limit keeps shrinking until it reaches 47 days in 2029. A second problem has nothing to do with dates: a certificate issued to other.example and served for example.com fails with a name mismatch even while it is in date.
Enter the host name in the SSL Certificate Checker. It makes one TLS handshake to port 443 with that name for SNI, then shows whether the certificate verified, the subject and alternative names, the issuer, the key type, and the validity dates. Days remaining are counted from the not-after date. Under 30 days the row is marked as soon, and under 7 days as due. If verification fails, the certificate is still parsed and shown with the reason beside it, so you can read the names and dates of a broken one too.
Before the renewal date, look the domain up in the CAA Record Lookup. CAA records name the certificate authorities that may issue for a domain. The issue tag covers host names, issuewild covers wildcards, and iodef is an address for reports. An empty issue value means no CA may issue at all. If you moved to a CA that isn't listed, a CA that honors CAA will refuse the renewal. A domain with no CAA records isn't restricted by this policy.
Enter the host name in the SSL Certificate Checker. It shows the not-after date and the days left, and marks the row when fewer than 30 days remain.
Public certificates issued from 15 March 2026 can be valid for at most 200 days. The certificate example.com served on 3 October 2026 ran from 26 September to 25 December 2026.
No. It means the name matches and a trusted issuer signed a certificate that is inside its dates. It says nothing about the page itself.
Yes. If the domain publishes CAA records and your CA isn't in an issue or issuewild row, a CA that honors CAA will refuse to issue.
Tools used in this guide
Subject, alternative names, issuer, validity, and key type for the certificate on port 443.
CAA issue, issuewild, and iodef values, with a short note on each tag.