SSL certificate checker
Check the HTTPS certificate on both the bare domain and www: when it expires, who issued it, the names it covers, and whether browsers trust it.
What this checks
- The certificate on the bare domain and on www, separately
- Valid from and valid to, with the days left
- The issuer, such as Let's Encrypt or Sectigo
- The names it covers (up to 20 are listed)
- That the chain is trusted and the certificate matches the name
An example, explained
Issuer: Let's Encrypt · Valid 1 Aug 2026 to 30 Oct 2026 · Names: example.co.uk, www.example.co.uk
- Issuer
- The certificate authority that signed it.
- Valid to
- After this date browsers show a full-page warning. Let's Encrypt certificates last 90 days or less and renew automatically, when renewal works.
- Names
- The names the certificate covers (subject alternative names). The address visitors use must be one of them.
Why certificates break
Most certificates now renew themselves, so a certificate expiring is rarely about someone forgetting. It's about renewal failing silently: the DNS moved, the site moved host, or a firewall blocks the check the certificate authority makes. The first anyone hears is a client ringing about a security warning.
That's why this checker looks at the bare domain and www separately. They're often served differently (www through a CDN, the bare domain by a redirect on the old host), and it's common for one to renew while the other lapses.
What each problem means
- Expiring or expired: renewal has stopped. See certificate expiring.
- Name mismatch: the certificate is for another name, often the hosting company's own. See certificate name mismatch.
- Not trusted: the certificate is self-signed, or the server isn't sending the intermediate certificate that links it to a trusted root. Some browsers paper over a missing intermediate; other software, including many email and API clients, won't. See certificate chain.
- No answer on port 443: there's no HTTPS site on that name. Fine if the name isn't used, but a www that doesn't answer loses visitors who type it.
This checker reads the certificate the server presents, the same way a browser does. It doesn't test cipher suites or protocol versions: it answers whether visitors will see a warning, now or soon.
Do this for every client, every day
- All nine checks on every client domain, daily, graded A to F
- Alerts by email or webhook when a grade drops or a record changes
- A monthly report card for each client, with your logo on it
- Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login
Start a free 28-day trial: up to 3 domains, no card needed.
Keep going
- Add domain and email health to your website care planThe guide
- Certificate expiringHow to fix it
- Certificate name mismatchHow to fix it
- Certificate chainHow to fix it
- Domain expiry checkerSee when a domain's registration runs out, who it's with, and its status.
- MTA-STS checkerCheck the MTA-STS record, the policy file and its certificate, and the MX match.
- DMARC checkerSee a domain's DMARC policy in plain English, and where its reports go.
- Free domain checkerAll nine checks on a domain, with a grade from A to F.
- Report cardsWhat your clients get each month, with your logo on it.
Questions
Why check www and the bare domain separately?
They're often served by different systems, so one certificate can renew while the other lapses. Visitors use both.
When do you warn about expiry?
For monitored domains, 21 days before a certificate expires, and again at 7. Most automatic renewals happen around 30 days before expiry, so a certificate inside 21 days has usually missed its renewal.
Does it check the protocol and cipher settings?
No. It checks the certificate: dates, issuer, names and trust. That's what decides whether visitors see a warning.
Why are only some names listed?
Shared hosting and CDN certificates can cover hundreds of names. We list the first 20 and give the total.
Do you keep a record of the domains I check?
No. The free checker keeps nothing.
Catch failed renewals before your clients do.
Start a free 28-day trial: up to 3 domains, no card needed.