Skip to content
JustTools

SSL Checker

See when a website’s SSL certificate expires, who issued it and which names it covers — and whether your browser trusts the site right now. Add a renewal reminder to your calendar in one click.

Looks up public records Free · no sign-up

At a glance

  • Shows a site’s SSL/TLS certificate: who issued it, the names it covers, when it was issued and when it expires, with the days left.
  • Warns when a certificate expires within 14 days, has been revoked, or can’t be found at all.
  • Tests the live site from your own browser: the HTTPS connection only succeeds when your browser trusts the certificate the server presents.
  • Checks DNS (IPv4 and IPv6) and CAA records, and whether they allow the current certificate authority to renew.
  • Adds a renewal reminder to your calendar (.ics) 14 days before expiry, and gives a shareable link to the result.
  • Certificate data comes from public Certificate Transparency logs via SSLMate’s Cert Spotter, and DNS from Google Public DNS. Only the domain name is sent.
  • Free with no sign-up. The log service allows up to 100 checks per hour from one network.

Step by step

How to check an SSL certificate

  1. 1

    Enter the domain

    Type a domain such as example.com, or paste any link from the site.

  2. 2

    Run the check

    Click Check SSL. The certificate logs, DNS and a live HTTPS connection are checked together in a few seconds.

  3. 3

    Read the result

    See whether the certificate is valid, when it expires, who issued it and which names it covers.

  4. 4

    Set a reminder

    Click Add renewal reminder to put the renewal date in your calendar, or Copy link to share the result.

Features

Everything you need, nothing you don’t

Expiry at a glance

The exact expiry date and time, days remaining, and how much of the certificate’s life has passed.

Live browser test

Your browser opens the site over HTTPS, so you know whether real visitors see a secure connection or a warning.

Every covered name

All domain names on the certificate, with the one you checked highlighted — including wildcard and multi-domain certificates.

CAA check

Finds CAA records (inherited from parent domains too) and warns if they would block your CA from renewing.

Never miss a renewal

One click adds a reminder to Google Calendar, Outlook or Apple Calendar two weeks before the certificate expires.

Shareable results

Each check has its own link, such as ?domain=example.com, to send to a developer or hosting company.

Understanding the result

ResultWhat it meansWhat to do
ValidA trusted certificate covers the name and has more than 14 days left.Nothing — set a renewal reminder if renewal isn’t automatic.
Expires soonFewer than 14 days are left on the newest certificate.Renew now, or check that automatic renewal is working.
RevokedThe certificate authority has withdrawn the certificate.Get a new certificate and install it.
No valid certificateNo trusted, unexpired certificate for this exact name is in the public logs.Check the spelling (www or not), then issue a certificate for the name.
Browser couldn’t connectYour browser couldn’t open the site over HTTPS.Open the site directly: a warning page means the server presents a bad certificate.

How this checker works

Browsers don’t let web pages read another site’s certificate, so the checker combines three public sources. Every certificate a public certificate authority issues is recorded in Certificate Transparency logs; the checker finds the valid ones for your domain and shows the newest, which is normally the one the server uses. DNS lookups confirm the domain exists and read its CAA records. Finally, your own browser makes an HTTPS request to the site, which only succeeds if it trusts the certificate the server actually presents.

It doesn’t test protocol versions, cipher suites or the certificate chain your server sends. For a full server audit, use a dedicated scanner such as Qualys SSL Labs.

FAQ

Frequently asked questions

How do I check when my SSL certificate expires?

Enter your domain and click Check SSL. The result shows the exact expiry date and time and the number of days left, and you can add a reminder to your calendar.

What is sent when I run a check?

Only the domain name: it is looked up in the Cert Spotter certificate logs and in Google Public DNS, and your browser requests the site’s home page over HTTPS. Nothing else is sent, and checks aren’t stored.

Why doesn’t my brand-new certificate show up?

Certificates reach the transparency logs within minutes of being issued, and the search service can take a little longer to index them. Try again in a few minutes.

The certificate is valid, so why couldn’t my browser connect?

The server may still present an old or misconfigured certificate, the site may be down, or it may refuse requests made by other websites. Open the site in a new tab: a security warning confirms a certificate problem.

How long are SSL certificates valid?

Let’s Encrypt certificates last 90 days. Under CA/Browser Forum rules, public certificates can be valid for at most 200 days from March 2026, falling in steps to 47 days by 2029 — so automatic renewal matters more than ever.

What is a CAA record?

A DNS record that lists which certificate authorities may issue certificates for your domain. If it doesn’t include your CA, renewals fail, so the checker warns you.

Does it work for subdomains and wildcard certificates?

Yes. Check any name such as shop.example.com; a wildcard certificate for *.example.com is found and shown as covering it.

Keep going

Browse every tool

Last updated Report a problem or suggest a feature