Skip to main content
WebTools

SSL certificate checker

Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.

Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.

What we check

We connect to the site on port 443 and make a secure (TLS) connection, checking the certificate the way a browser does: that it was issued by a trusted authority, that it covers the name you entered, and that it is in date. If that fails, we make a second connection only to explain what is wrong. That second connection never counts as a pass.

Common problems

Expiry warnings

We add a note when a valid certificate has 30 days or fewer left, and show Attention at 14 days or fewer.

Frequently asked questions

What is the difference between SSL and TLS?

TLS is the modern version of SSL. People still say "SSL certificate", but every secure website today uses TLS 1.2 or TLS 1.3. The certificate is the same either way.

Why does it say the intermediate certificate is missing?

Servers should send their own certificate plus the intermediate certificate(s) that link it to a trusted root. Some browsers can find a missing intermediate themselves, but many apps, scripts and older devices can't, so they will reject the site. Install the full chain (often called "fullchain") on the server.

How early should I renew a certificate?

Most automated certificates renew about 30 days before expiry. We show a note at 30 days and Attention at 14 days or fewer, because a renewal that hasn't happened by then may have failed.

Does a valid certificate mean the site is safe?

No. A valid certificate means the connection is encrypted and the certificate was issued for that name by a trusted authority. It says nothing about whether the site itself is honest or secure.

Which port do you check?

Port 443, the standard HTTPS port. Other ports can't be checked.

  • Website Down Checker

    Check whether a website is responding right now, from our server: status, response time, redirects, IP addresses and HTTPS.

  • Security Header Checker

    Check which browser security headers a website sends (HSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) and what they do.

  • Redirect Checker

    Follow a web address through every redirect, with the status code, destination and timing of each hop.

  • HTTP Header Checker

    See the HTTP status and every response header a website sends, for the final page and each redirect on the way.

  • CAA Checker

    See which certificate authorities a domain allows to issue its certificates.

  • DNSSEC Checker

    Check whether a domain is signed with DNSSEC and whether validating resolvers accept it.

  • DNS Lookup

    Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.

  • MX Lookup

    See which mail servers receive email for a domain, in priority order, with each server's addresses.

  • SPF Checker

    Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.

  • DMARC Checker

    Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.

  • Website Health Check

    Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.