SSL Checker
Verify your website's SSL/TLS installation. Inspect expiration dates, certificate authorities, common names, and identify potential handshake issues instantly.
What is an SSL Certificate?
An SSL (Secure Sockets Layer) certificate is a digital key card that verifies a website's identity and sets up an encrypted connection. Think of it as a sealed envelope for your digital correspondence. It secures the lane between a user's browser and the host server.
Without a valid certificate, your data travels in plain text, making it easy for hackers on the same network to read passwords, numbers, or emails. When installed, it changes the browser bar from HTTP to HTTPS and shows a secure padlock icon.
Why should you inspect your certificate?
Prevent visitor browser warnings
If your certificate expires or is set up wrong, browsers block users with a major warning. Running regular checks helps you renew certificates before they disrupt your site traffic.
Track exact expiration dates
Since 15 March 2026, publicly trusted certificates can be valid for at most 200 days (that limit falls to 100 days in 2027 and 47 days in 2029). Let's Encrypt certificates currently last 90 days by default. Keep tabs on the remaining days so your automated setups never fail you.
Check name matching values
A common issue is a certificate that secures example.com but ignores www.example.com. Our check lists every alternative name (SAN) on the certificate, so you can confirm each hostname you serve is covered.
Confirm trustworthy issuers
Validate that your certificate was issued by a recognized root authority (like Google, Let's Encrypt, or DigiCert) so browsers accept your handshake without questions.
How to run a check
Enter domain name
Input the domain address you want to inspect above and press check. Do not worry about adding HTTP or HTTPS.
Inspect details
Review the common name, issuer, alternative names, and validity dates to confirm everything looks correct.
Confirm remaining days
Take note of the expiration date to prevent unexpected security warnings for your web visitors.
Frequently Asked Questions
Why does my website need an SSL certificate?
An SSL certificate encrypts the connection between your visitors' browsers and your server, protecting sensitive information like login details, credit cards, and form inputs. Browsers will also mark your website as 'Not Secure' if you do not have one, which ruins user trust.
What is the difference between SSL and TLS?
TLS (Transport Layer Security) is simply the modern, updated version of SSL (Secure Sockets Layer). Although everyone still refers to them as SSL certificates for convenience, all modern HTTPS certificates actually use the newer, more secure TLS protocol behind the scenes.
How long do SSL certificates last?
Since 15 March 2026, publicly trusted SSL/TLS certificates can be valid for a maximum of 200 days, down from 398. Under the CA/Browser Forum schedule, that falls to 100 days in March 2027 and 47 days in March 2029. Let's Encrypt currently issues 90-day certificates by default. Shorter lifetimes limit how long a compromised or mis-issued certificate stays usable, and push site owners to automate renewal.
What is a wildcard SSL certificate?
A wildcard SSL certificate allows you to secure a main domain and an unlimited number of its subdomains with a single file. For example, a wildcard certificate for *.example.com will automatically protect blog.example.com, shop.example.com, and mail.example.com.
What does a "Certificate Authority" (CA) do?
A Certificate Authority is a trusted organization that verifies websites and issues SSL certificates to them. Before giving out a certificate, the CA checks to make sure that you actually own the domain, preventing hackers from pretending to be your website.
What happens when an SSL certificate expires?
If a certificate expires, browsers will block visitors with a large, scary warning saying their connection is not private. Most visitors will leave rather than click through, so traffic and trust drop until the certificate is renewed. Visitors who do click through lose the guarantee that they're talking to the real site.
