Security Tools

SSL Certificate Checker

Inspect the certificate a website serves to its visitors. The checker connects to the host, reads the certificate and its chain, and tells you whether it is trusted, whether it matches the name, when it expires and how strong its key is.

  • Encrypted connection
  • No sign-up
  • Free to use

The certificate is read from a live connection to port 443 of the host.

How to use SSL Certificate Checker

  1. Enter a domain or host name. A full web address works as well.
  2. Select Check certificate.
  3. Read the verdict and the checks: trust, host name match, expiry, key and protocol.
  4. Review the certificate details, the names it covers and the chain sent by the server.

SSL Certificate Checker features

Live handshake

The certificate is taken from a real TLS connection to port 443, not from a database.

Trust verification

Confirms that the chain leads to a publicly trusted root authority.

Host name match

Checks the name against the subject alternative names, including wildcards.

Expiry countdown

Days remaining, with warnings at 30 and 14 days.

Key and signature strength

Key type and size, signature algorithm and the TLS version negotiated.

Chain display

Every certificate the server sent, in order, with its issuer and expiry.

When to use SSL Certificate Checker

  • Confirming that a newly installed or renewed certificate is active.
  • Finding the cause of a browser warning such as “Your connection is not private”.
  • Checking which subdomains a certificate covers before adding a new one.
  • Verifying that a hosting provider or CDN serves the right certificate for your domain.

SSL Certificate Checker FAQ

What is the difference between SSL and TLS?

TLS is the successor of SSL. The SSL protocols themselves were retired years ago, and every secure connection today uses TLS 1.2 or 1.3. The older name stuck, so “SSL certificate” and “TLS certificate” mean the same thing.

Why is a certificate not trusted?

The usual reasons are a self-signed certificate, an expired certificate, or a server that does not send the intermediate certificate linking it to a trusted root. The last one is easy to miss, because some browsers fetch missing intermediates themselves while other clients fail.

What does “host name mismatch” mean?

The certificate is valid but issued for different names. It happens when a certificate for example.com is used on www.example.com without listing that name, or when a server shows a default certificate because the site is not configured for HTTPS.

How long are certificates valid?

Publicly trusted certificates are limited to 398 days, and free authorities such as Let's Encrypt issue them for 90 days. Shorter lifetimes are the industry trend, which makes automatic renewal essential.

What is a wildcard certificate?

A certificate for *.example.com covers every direct subdomain, such as shop.example.com and mail.example.com. It does not cover the bare domain unless that is listed separately, and it does not cover deeper levels like a.b.example.com.

Does the checker test the whole server configuration?

It evaluates the certificate, the chain and the protocol version of one connection. It does not enumerate every cipher suite the server supports or test for specific protocol vulnerabilities.

What a certificate proves

When a browser connects to a site over HTTPS, the server presents a certificate: a signed statement that a particular public key belongs to particular host names. The browser checks three things before it shows the padlock. The certificate must be within its validity period, it must list the name in the address bar, and it must be signed, through a chain of intermediate certificates, by an authority the device already trusts. If any one of these fails, the visitor sees a full-page warning.

Most certificate problems fall into a few categories. Expiry is the most common, usually because an automatic renewal silently stopped. Name mismatches appear after a site is moved or a new subdomain is added. Incomplete chains are the trickiest, since the site may work in one browser and fail in another, in mobile apps or in API clients. The chain table on this page shows exactly what the server sends, which makes a missing intermediate obvious.

The strength of the key and the signature matters less often today, because certificate authorities no longer issue weak ones, but old or internal certificates can still fall short. An RSA key should have at least 2048 bits, the signature should use SHA-256 or better, and the connection should negotiate TLS 1.2 or 1.3.

A valid certificate secures the connection; it says nothing about who runs the site. Certificates are issued automatically to anyone who controls a domain, including fraudsters. The padlock means that nobody can read or alter the traffic on the way, not that the destination is trustworthy.

Other useful tools