SSL Checker
Check any website's SSL certificate: whether browsers trust it, when it expires, the full chain and which TLS versions the server accepts.
Checks port 443 unless you add another, like imap.gmail.com:993.
Enter a domain to check its SSL certificate.
We'll tell you whether browsers trust it, when it expires and what the server supports.
What is an SSL Checker?
An SSL Checker is a tool that allows you to verify the SSL certificate details of a website. It checks certificate validity, issuer, expiration date, encryption strength, and server configuration to ensure a secure HTTPS connection.
Why Use an SSL Checker?
- Verify if a website is using a valid SSL certificate
- Check certificate expiration date
- View issuer and certificate chain
- Identify SSL/TLS version and cipher suite
- Troubleshoot SSL-related issues
What an SSL checker tells you
The padlock in the address bar only appears when a site's certificate passes a few tests: a trusted authority issued it, it covers the name you typed, and it hasn't expired. When one of those fails, visitors get a full-page warning instead of your site. An SSL checker runs the same tests on demand, so you can see exactly what's wrong, or confirm that nothing is, before your visitors notice.
It's the quickest way to confirm a new certificate was installed correctly, to find out when one expires, to work out why one device shows a warning when another doesn't, and to see whether a server still accepts outdated versions of TLS.
How this SSL checker works
We open a TLS connection from our server to the domain, the same handshake a browser makes, and read the certificate it presents along with the rest of the chain. Then we verify it against the same list of trusted authorities that browsers use, check that it covers the name you entered, and compare its dates with today. A few extra short handshakes find out which TLS versions the server will accept. No web page is requested and nothing is sent once the certificate has been read.
The result is six checks, each a clear pass or fail:
- Trusted by browsers: the chain leads to a root certificate authority that browsers trust.
- Covers the domain: the name you checked is listed on the certificate.
- Not expired: today falls inside its validity dates. We flag anything with 14 days or less left.
- Complete chain sent: the server includes the intermediate certificate, not just its own.
- Modern TLS only: TLS 1.2 and 1.3 are on, and the retired TLS 1.0 and 1.1 are off.
- Strong key and signature: an RSA key of at least 2048 bits or an elliptic-curve key, and no SHA-1.
Common SSL errors and how to fix them
The certificate has expired
The most common cause of a sudden "Your connection is not private" page. Renew it, install the new files and reload the web server. If you use Let's Encrypt or another ACME client, check why the automatic renewal stopped: an expired DNS record, a firewall blocking port 80, or a renewal job that no longer runs.
The name doesn't match
The certificate covers different names than the one you visited. A frequent case is a certificate for example.com but not www.example.com, or the other way round. A wildcard like *.example.com covers one level only: it covers shop.example.com but not example.com itself or a.b.example.com. Reissue the certificate with every name you serve.
The chain is incomplete
The server sends its own certificate but not the intermediate that links it to a trusted root. Desktop browsers sometimes cover for this, phones and apps usually don't, so the site works for some people and not others. Install the full chain file (often called fullchain.pem or a CA bundle) instead of the certificate alone.
The certificate is self-signed
No certificate authority vouches for it. That's fine for a test machine you control, never for a public site. A free certificate from Let's Encrypt or your host fixes it.
The root isn't trusted
The chain ends at a certificate authority that browsers don't include, usually a company's internal CA. Visitors outside that company will always see a warning. Public sites need a certificate from a publicly trusted CA.
The certificate isn't valid yet
Its start date is in the future. Either the certificate was installed early, or the server's clock is wrong. Check the time and time zone on the server.
Certificates are getting shorter
Public certificates used to last up to 398 days. Under a schedule agreed by the CA/Browser Forum, the maximum is coming down in three steps, which makes automatic renewal close to essential:
| Issued on or after | Longest validity |
|---|---|
| 15 March 2026 | 200 days |
| 15 March 2027 | 100 days |
| 15 March 2029 | 47 days |
If your certificates are renewed by hand, now is the time to switch to an ACME client such as Certbot, or to your host's built-in automatic renewal, and to check expiry dates regularly until you trust the automation.
The certificate chain, explained
Browsers don't trust your certificate directly. They trust a short list of root certificate authorities, and each root signs intermediate certificates, which in turn sign certificates like yours. When a browser connects, it needs the whole path: your certificate, then the intermediate, then a root it already has. The server is responsible for sending your certificate and the intermediate. Forget the intermediate and the path breaks, which is why “works on my laptop, fails on my phone” is so often a chain problem.
TLS versions
TLS 1.3 is the current version: faster to connect and with fewer, safer options. TLS 1.2 is still perfectly fine. TLS 1.0 and 1.1 were formally retired in 2021 and browsers no longer use them, so a server that still accepts them gains nothing and keeps weaker options open. Mail servers are the usual place they linger.
Check a certificate yourself
With OpenSSL installed, these show the same information from your own machine:
openssl s_client -connect example.com:443 -servername example.comshows the chain and verification result.- Add
| openssl x509 -noout -subject -issuer -datesto print just the names and dates. curl -vI https://example.comshows the handshake and any certificate error in a single line.
Related checks
A valid certificate is only part of a healthy site. The website status checker confirms the site responds, the HTTP header checker shows whether HSTS is set to keep visitors on HTTPS, and the port checker tells you whether port 443 is reachable at all.
Frequently asked questions
How do I check if an SSL certificate is valid?
Enter the domain above and run the check. We connect to the server, read its certificate and verify it the way a browser does: is it trusted, does it cover that name, and is it inside its validity dates. Each result is shown as a pass or fail with a plain explanation.
How do I check when an SSL certificate expires?
Run the check and look at the expiry line, which shows the exact date and how many days are left. Certificates now last at most 200 days, and that limit keeps shrinking, so it's worth checking any certificate that isn't renewed automatically.
Why does my site show "Not secure" even though it has a certificate?
Usually because the certificate has expired, doesn't cover the exact name in the address bar, or is missing its intermediate certificate. The check above tells you which. If the certificate passes everything, the page may be loading some images or scripts over plain http, which browsers also flag.
What is an incomplete certificate chain?
Your certificate is signed by an intermediate certificate authority, which is signed by a root that browsers trust. The server has to send the intermediate along with your certificate. If it doesn't, some browsers and most apps can't build the path to the root and reject the connection.
Is SSL the same as TLS?
In everyday use, yes. SSL was the original protocol and was replaced by TLS years ago, but the name stuck. When people say SSL certificate today, they mean the certificate used by TLS. The certificate is the same either way.
Which TLS versions should a server support?
TLS 1.2 and TLS 1.3. TLS 1.0 and 1.1 were formally retired in 2021 and every major browser has dropped them, so leaving them switched on only helps attackers. The check shows exactly which versions your server accepts.
What's the difference between DV, OV and EV certificates?
They differ in how much the certificate authority checked before issuing. DV only confirms you control the domain. OV also confirms the organisation exists. EV involves a deeper check of the company. Browsers show the padlock the same way for all three, and the encryption is identical.
Can I check a mail server or another port?
Yes. Add the port after the domain, for example imap.gmail.com:993. Supported TLS ports are 443, 8443, 465 (SMTPS), 993 (IMAPS), 995 (POP3S), 636 (LDAPS), 990 (FTPS) and 853 (DNS over TLS).
How long do SSL certificates last now?
Since 15 March 2026, newly issued public certificates can be valid for at most 200 days. That drops to 100 days in March 2027 and 47 days in March 2029, under rules agreed by the CA/Browser Forum. In practice this means renewal has to be automated.
Is it safe to check any website?
Yes. We only perform the TLS handshake that any browser does when it connects, read the certificate and close the connection. No page is requested and nothing is sent. Checks are rate-limited, and only public addresses can be checked.

