Skip to content
Free, no sign-up

SSL certificate checker

Check the HTTPS certificate on both the bare domain and www: when it expires, who issued it, the names it covers, and whether browsers trust it.

What this checks

  • The certificate on the bare domain and on www, separately
  • Valid from and valid to, with the days left
  • The issuer, such as Let's Encrypt or Sectigo
  • The names it covers (up to 20 are listed)
  • That the chain is trusted and the certificate matches the name

An example, explained

Certificate on www.example.co.uk
Issuer: Let's Encrypt · Valid 1 Aug 2026 to 30 Oct 2026 · Names: example.co.uk, www.example.co.uk
Issuer
The certificate authority that signed it.
Valid to
After this date browsers show a full-page warning. Let's Encrypt certificates last 90 days or less and renew automatically, when renewal works.
Names
The names the certificate covers (subject alternative names). The address visitors use must be one of them.

Why certificates break

Most certificates now renew themselves, so a certificate expiring is rarely about someone forgetting. It's about renewal failing silently: the DNS moved, the site moved host, or a firewall blocks the check the certificate authority makes. The first anyone hears is a client ringing about a security warning.

That's why this checker looks at the bare domain and www separately. They're often served differently (www through a CDN, the bare domain by a redirect on the old host), and it's common for one to renew while the other lapses.

What each problem means

  • Expiring or expired: renewal has stopped. See certificate expiring.
  • Name mismatch: the certificate is for another name, often the hosting company's own. See certificate name mismatch.
  • Not trusted: the certificate is self-signed, or the server isn't sending the intermediate certificate that links it to a trusted root. Some browsers paper over a missing intermediate; other software, including many email and API clients, won't. See certificate chain.
  • No answer on port 443: there's no HTTPS site on that name. Fine if the name isn't used, but a www that doesn't answer loses visitors who type it.

This checker reads the certificate the server presents, the same way a browser does. It doesn't test cipher suites or protocol versions: it answers whether visitors will see a warning, now or soon.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

Why check www and the bare domain separately?

They're often served by different systems, so one certificate can renew while the other lapses. Visitors use both.

When do you warn about expiry?

For monitored domains, 21 days before a certificate expires, and again at 7. Most automatic renewals happen around 30 days before expiry, so a certificate inside 21 days has usually missed its renewal.

Does it check the protocol and cipher settings?

No. It checks the certificate: dates, issuer, names and trust. That's what decides whether visitors see a warning.

Why are only some names listed?

Shared hosting and CDN certificates can cover hundreds of names. We list the first 20 and give the total.

Do you keep a record of the domains I check?

No. The free checker keeps nothing.

Catch failed renewals before your clients do.

Start a free 28-day trial: up to 3 domains, no card needed.