Website HTTPS Checker
Check everything that makes a site properly secure in one go. The checker loads the home page over HTTPS, verifies that the certificate is trusted, covers the host and is not about to expire, tests whether http:// redirects permanently to https://, reads the Strict-Transport-Security header and its max-age, includeSubDomains and preload flags, reports the negotiated TLS version and counts http:// resources on the home page. A weighted score sums it up.
- Encrypted connection
- No sign-up
- Free to use
How to use Website HTTPS Checker
- Enter the domain.
- Click “Check HTTPS”.
- Read the score and checks.
- Fix redirects, HSTS or certificate issues.
Website HTTPS Checker features
Certificate
Trust, names and expiry.
Redirect
http → https, permanent.
HSTS
max-age, subdomains, preload.
TLS version
Negotiated protocol.
Mixed content
On the home page.
Safe fetching
Public addresses only, with size and time limits.
When to use Website HTTPS Checker
- Launch checks.
- After moving to HTTPS.
- Certificate renewal monitoring.
- Security reviews.
Website HTTPS Checker FAQ
Why must http redirect to https?
Visitors who type the address without https would otherwise use an unencrypted connection.
What is HSTS?
A header that tells browsers to use HTTPS for the site for a set time, even if a link says http.
What max-age should HSTS have?
At least six months (15552000 seconds); one or two years for preload.
Should I use 301 or 302?
A permanent redirect – 301 or 308.
HTTPS done properly
A certificate alone is not enough: without a redirect and HSTS, the first request can still go over plain HTTP. All three together make the connection reliably encrypted.
Automated renewal with an ACME client such as Certbot prevents expired certificates.
How it works: our server downloads the page once through a guarded fetcher that only connects to public addresses, follows a limited number of redirects and stops after a size and time limit. The HTML is then analysed in your browser as inert text – scripts on the page never run and nothing is stored.
What it cannot see: content and resources that a page adds with JavaScript after it loads, pages behind a login, and servers that block automated requests. For those, open the page in your browser, use its developer tools, or paste the page source where the tool offers a paste option.
Use the results as a starting point: fix the items marked red first, review the yellow warnings in context, and run the check again after a change. Requests are rate-limited to keep the service fair; if you check many pages in a row, wait a few minutes.
Related checks on this site cover the rest of a technical review – speed and Core Web Vitals, security headers, structured data, accessibility and SEO signals – so you can work through a whole site audit one topic at a time.
Who it is for: site owners checking their own pages, developers debugging a release, SEO and marketing teams auditing clients or competitors, and students learning how the web works. No account or installation is needed, and the results are plain text and tables you can copy into a report or ticket.