What the SSL checker tests
The padlock in the address bar depends on one file: the site's TLS certificate, still called an SSL certificate by most people. This SSL checker connects to the domain on port 443 like a browser and runs two tests. The first verifies the certificate the way browsers do: is it signed by a trusted authority, does it cover this domain name, and is it within its dates. The second reads the certificate and the chain without judging them, so you see the details even when something is wrong.
You get the issuer, the expiry date with the days left, every domain name in the SAN list, the key type, the TLS version and cipher of the connection, and each certificate in the chain the server sends. Pair it with the HTTP header checker to make sure http redirects to https and HSTS is set, and with the DNS lookup to see the CAA records that decide which authorities may issue certificates for the domain.
Common certificate problems
| Problem | What it means and what to do |
|---|---|
| Expired | The end date has passed. Automatic renewal failed or was never set up. Renew the certificate and reload the web server. |
| Name mismatch | The certificate is for other names, for example only www.example.com but not example.com. Issue one that lists every name you use. |
| Incomplete chain | The server sends only its own certificate, not the intermediate one. Desktop browsers often cope, phones and apps fail. Install the full chain. |
| Self-signed | Nobody vouches for the certificate. Fine for testing, never for a public site. Use a free certificate from Let’s Encrypt or your host. |
| Old TLS version | TLS 1.0 and 1.1 are switched off in all current browsers. The server needs TLS 1.2 or 1.3. |
Never miss an expiry date
An expired certificate takes a site offline for most visitors: browsers show a full-page warning that few people click through. Free certificates from Let's Encrypt renew automatically when the setup works, so the danger is a renewal that silently stopped after a server move or a DNS change. Check your domains once a month, or after any change to hosting, and set a calendar reminder two weeks before the expiry date of any certificate you renew by hand.
How to check an SSL certificate
- 1Type the domain, or paste a link from the site; only the host name is used.
- 2Read the verdict and the days left, then the findings, which explain anything a browser would complain about.
- 3Check the names list covers every address you use, with and without www, and that the chain has an intermediate.
Frequently asked questions
How many days before expiry should a certificate be renewed?
Let’s Encrypt certificates currently last 90 days, with shorter lifetimes on the way, and are renewed automatically about a third of their lifetime before they end. Paid certificates last up to about a year and are renewed by hand or by your host. If the checker shows fewer than 14 days left on an automatic certificate, renewal is probably failing and needs a look.
What is the certificate chain?
Browsers trust a short list of root authorities. A root signs an intermediate certificate, and the intermediate signs your site’s certificate. Your server must send its own certificate plus the intermediate, so the browser can link it to a root it knows. The root itself is already in the browser.
What are SANs?
Subject Alternative Names are the list of domain names a certificate is valid for. Browsers only look at this list. A wildcard entry like *.example.com covers one level of subdomains, such as shop.example.com, but not example.com itself and not a.b.example.com.
Does a valid certificate mean the site is safe?
No. It means the connection is encrypted and that the certificate was issued for this domain. Anyone can get a certificate for a domain they control, including scammers. It says nothing about who runs the site or whether it is honest.
Can I check a server on another port or an IP address?
This checker connects to port 443 of a public domain name only, the standard port for https. Mail servers, other ports and internal addresses are not supported.