SSL Checker
See when a website’s SSL certificate expires, who issued it and which names it covers — and whether your browser trusts the site right now. Add a renewal reminder to your calendar in one click.
At a glance
- Shows a site’s SSL/TLS certificate: who issued it, the names it covers, when it was issued and when it expires, with the days left.
- Warns when a certificate expires within 14 days, has been revoked, or can’t be found at all.
- Tests the live site from your own browser: the HTTPS connection only succeeds when your browser trusts the certificate the server presents.
- Checks DNS (IPv4 and IPv6) and CAA records, and whether they allow the current certificate authority to renew.
- Adds a renewal reminder to your calendar (.ics) 14 days before expiry, and gives a shareable link to the result.
- Certificate data comes from public Certificate Transparency logs via SSLMate’s Cert Spotter, and DNS from Google Public DNS. Only the domain name is sent.
- Free with no sign-up. The log service allows up to 100 checks per hour from one network.
Step by step
How to check an SSL certificate
- 1
Enter the domain
Type a domain such as example.com, or paste any link from the site.
- 2
Run the check
Click Check SSL. The certificate logs, DNS and a live HTTPS connection are checked together in a few seconds.
- 3
Read the result
See whether the certificate is valid, when it expires, who issued it and which names it covers.
- 4
Set a reminder
Click Add renewal reminder to put the renewal date in your calendar, or Copy link to share the result.
Features
Everything you need, nothing you don’t
Expiry at a glance
The exact expiry date and time, days remaining, and how much of the certificate’s life has passed.
Live browser test
Your browser opens the site over HTTPS, so you know whether real visitors see a secure connection or a warning.
Every covered name
All domain names on the certificate, with the one you checked highlighted — including wildcard and multi-domain certificates.
CAA check
Finds CAA records (inherited from parent domains too) and warns if they would block your CA from renewing.
Never miss a renewal
One click adds a reminder to Google Calendar, Outlook or Apple Calendar two weeks before the certificate expires.
Shareable results
Each check has its own link, such as ?domain=example.com, to send to a developer or hosting company.
Understanding the result
| Result | What it means | What to do |
|---|---|---|
| Valid | A trusted certificate covers the name and has more than 14 days left. | Nothing — set a renewal reminder if renewal isn’t automatic. |
| Expires soon | Fewer than 14 days are left on the newest certificate. | Renew now, or check that automatic renewal is working. |
| Revoked | The certificate authority has withdrawn the certificate. | Get a new certificate and install it. |
| No valid certificate | No trusted, unexpired certificate for this exact name is in the public logs. | Check the spelling (www or not), then issue a certificate for the name. |
| Browser couldn’t connect | Your browser couldn’t open the site over HTTPS. | Open the site directly: a warning page means the server presents a bad certificate. |
How this checker works
Browsers don’t let web pages read another site’s certificate, so the checker combines three public sources. Every certificate a public certificate authority issues is recorded in Certificate Transparency logs; the checker finds the valid ones for your domain and shows the newest, which is normally the one the server uses. DNS lookups confirm the domain exists and read its CAA records. Finally, your own browser makes an HTTPS request to the site, which only succeeds if it trusts the certificate the server actually presents.
It doesn’t test protocol versions, cipher suites or the certificate chain your server sends. For a full server audit, use a dedicated scanner such as Qualys SSL Labs.
FAQ
Frequently asked questions
How do I check when my SSL certificate expires?
What is sent when I run a check?
Why doesn’t my brand-new certificate show up?
The certificate is valid, so why couldn’t my browser connect?
How long are SSL certificates valid?
What is a CAA record?
Does it work for subdomains and wildcard certificates?
Keep going
Related tools
Password Generator
Generate strong, random passwords, memorable passphrases and PINs with a cryptographically secure generator. Free, instant and private — nothing is stored.
XML to JSON Converter
Convert XML to JSON and JSON to XML online. Keeps attributes, arrays and leading zeros intact, shows exact error lines and never uploads your data.
JSON Formatter & Validator
Format, validate, minify and repair JSON online. Get the exact line and column of every error, a collapsible tree view and sorted keys — private, in-browser.
Image Steganography Tool
Hide a secret message or file inside an image, protected with a password, and reveal hidden messages from PNG images. Free and private — no upload.
Password Strength Checker
Check how strong a password is: time to crack, common words and patterns it hides, tips to improve it, and a safe data-breach check. Fully private.
PPK to PEM Converter
Convert a PuTTY .ppk private key to PEM or OpenSSH format online, with or without a passphrase. Supports PPK v2 and v3, RSA, ECDSA and Ed25519. No upload.
Last updated Report a problem or suggest a feature