Free tool
SSL certificate checker
Enter a domain to read the SSL/TLS certificate it serves on port 443: the issuer, the expiry date, how many days are left, the hostnames it covers and whether browsers will trust it. Free, no signup.
What this SSL checker does
The checker opens a TLS connection to the domain on port 443, the same handshake a browser performs, and reads the certificate the server presents. It does not load the page or send any data to the site. The result shows the certificate's notAfter date (when it expires), the number of whole days left, the certificate authority that issued it, the date it became valid, the DNS names listed in its Subject Alternative Name field and the TLS version that was negotiated.
It also tells you whether a browser would trust the certificate. A certificate can still be inside its validity dates and fail anyway: if it doesn't list the hostname you typed, if it's self-signed, or if the server forgets to send the intermediate certificate, visitors get a full-page warning instead of your site.
Why SSL certificate expiry matters
When a certificate expires, every modern browser blocks the page with a security warning such as "Your connection is not private". Most visitors leave. Checkout, login and contact forms stop working, API clients and webhooks start failing, and search engines may stop showing the page while it's broken.
Certificates are short-lived on purpose. Let's Encrypt and many other free authorities issue 90-day certificates, and the CA/Browser Forum has voted to keep reducing the maximum lifetime of all public certificates over the next few years. Shorter lifetimes are safer, but they mean renewal has to work every time. Auto-renewal usually does, until a DNS change, a firewall rule, a moved server or an expired API token quietly breaks it.
How to read the result
- Days left: green above 30 days, amber at 30 days or fewer, red at 7 days or fewer or once expired. If you rely on auto-renewal and see amber, renewal has probably already failed at least once.
- Issuer: the certificate authority (for example Let's Encrypt, Google Trust Services, Sectigo or DigiCert). An issuer you don't recognise on a domain you control is worth investigating.
- Covers: the hostnames in the certificate. If you typed www.example.com and only example.com is listed, the www address will show a warning.
- Trusted by browsers: "No" with a reason means visitors would see an error even if the dates look fine.
How to fix common SSL problems
- 01Expired or expiring soon: renew in your host or CDN dashboard, or run your ACME client by hand (for example certbot renew) and read the error it prints. Then reload the web server so it serves the new file.
- 02Hostname not covered: reissue the certificate with every name visitors use, usually both example.com and www.example.com, or redirect the uncovered name somewhere that is covered.
- 03Missing intermediate: configure the full chain file (often fullchain.pem) instead of the single certificate. Desktop browsers sometimes hide this problem; phones and API clients usually don't.
- 04Self-signed: replace it with a certificate from a public authority. Let's Encrypt is free and supported by most hosts.
- 05Renewed but still old: a CDN, load balancer or second server may still hold the old certificate. Check each one, then run this checker again.
Check a certificate from the command line
If you prefer a terminal, OpenSSL prints the same dates and issuer:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -issuer -datesFrequently asked questions
- Is this SSL checker free?
- Yes. It's free and needs no account. To keep it fair for everyone, each visitor can run up to 10 checks a minute and 100 a day across our free tools.
- How do I check when an SSL certificate expires?
- Type the domain into the checker above and press Check SSL. The Expires field is the certificate's expiry date and the large number is how many days are left. In a browser you can also click the padlock and open the certificate details, one site at a time.
- Does the checker store my domain?
- Results are cached for about 10 minutes so repeat lookups are fast, and are not saved to an account. Like any web server we keep short-lived request logs and a per-IP counter for rate limiting.
- Why does a browser say the certificate is invalid when the dates are fine?
- The usual causes are a hostname that isn't listed in the certificate, a missing intermediate certificate or a self-signed certificate. The "Trusted by browsers" row shows which one applies.
- How often should I check my SSL certificate?
- Certificates that renew every 90 days are worth checking at least weekly. Websites With Punch reads the certificate of every site you add once a day and shows the days left on your dashboard, amber at 30 days and red at 7.
- Can I check a certificate on a port other than 443?
- This free tool checks port 443, where public HTTPS sites serve their certificate. IP addresses, localhost and private networks can't be checked.
More free tools and guides
- Domain expiry checker →Registrar, expiry date and days left, read live from the registry over RDAP.
- Website down checker →Is it down for everyone or just you? Status code, response time and redirects.
- Uptime monitoring →A daily check of every site, on-demand rechecks, auto refresh and 90 days of history.
- SSL certificate monitoring →Days left on every certificate you look after, amber at 30 days and red at 7.