SSL Certificate Checker

Read the TLS certificate on port 443: the names it covers, who issued it, and when it expires.

This check runs on our server. The address you enter is used only for this check and is not stored.
Updated

This check runs on our server. The address you enter is used only for this check and is not stored.

How to use the SSL Certificate Checker

  1. Enter a host name.
  2. Tick the robot check and press Check.
  3. Read whether it verified, then the names, the issuer, and the expiry.

How it works

This check runs on our server. The host is not stored.

One TLS handshake goes to port 443, with the host name used for SNI. The certificate is checked against that name and against the trust store. If verification fails, the certificate is still parsed and shown, with the reason beside it. Days remaining come from the not-after date. Under 30 days the row is marked as soon. Under 7 days it is marked as due.

Examples

  • A current certificate for example.com lists that name, or *.example.com, under the alternative names, with an issuer and a not-after date.
  • A certificate issued to other.example and served for example.com shows a name mismatch and still lists other.example.
  • A certificate whose not-after date has passed shows expired, with the date.

Limitations

  • Port 443 only. Mail ports and other TLS ports are out of scope.
  • One host per check. The chain is the chain the server sent, plus what verification could build.
  • A host that does not complete the handshake has no certificate to show. The page says the connection failed.

Frequently asked questions

Does a valid certificate mean the site is safe?

It means the name matches and a trusted issuer signed a certificate that is inside its dates. It does not review the page.

Why can I see a certificate that failed verification?

The server still sent one. Hiding it would leave you without the names and the dates.

Do you store the host?

No.

Often used together with the SSL Certificate.

  • HTTP Headers

    Status, final URL, and response headers from one GET.

  • HTTP Check

    HTTP status and response time from each available location, without downloading the page.

  • Whois Lookup

    Registrar, domain status, name servers, and dates from the registry's RDAP record.