SSL certificate checker
Check whether a site's HTTPS certificate is valid and trusted, which names it covers, and when it expires.
Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.
What we check
We connect to the site on port 443 and make a secure (TLS) connection, checking the certificate the way a browser does: that it was issued by a trusted authority, that it covers the name you entered, and that it is in date. If that fails, we make a second connection only to explain what is wrong. That second connection never counts as a pass.
Common problems
- Expired: the certificate's end date has passed. Automated renewal may have stopped working.
- Doesn't cover this name: the certificate is for other names, often because www or a subdomain was left off.
- Missing intermediate certificate: the server sends its own certificate but not the link to a trusted root. Install the full chain.
- Self-signed or untrusted: the certificate wasn't issued by an authority browsers trust.
- No secure connection: the server only offers old TLS versions, or doesn't serve HTTPS for this name.
Expiry warnings
We add a note when a valid certificate has 30 days or fewer left, and show Attention at 14 days or fewer.
Frequently asked questions
What is the difference between SSL and TLS?
TLS is the modern version of SSL. People still say "SSL certificate", but every secure website today uses TLS 1.2 or TLS 1.3. The certificate is the same either way.
Why does it say the intermediate certificate is missing?
Servers should send their own certificate plus the intermediate certificate(s) that link it to a trusted root. Some browsers can find a missing intermediate themselves, but many apps, scripts and older devices can't, so they will reject the site. Install the full chain (often called "fullchain") on the server.
How early should I renew a certificate?
Most automated certificates renew about 30 days before expiry. We show a note at 30 days and Attention at 14 days or fewer, because a renewal that hasn't happened by then may have failed.
Does a valid certificate mean the site is safe?
No. A valid certificate means the connection is encrypted and the certificate was issued for that name by a trusted authority. It says nothing about whether the site itself is honest or secure.
Which port do you check?
Port 443, the standard HTTPS port. Other ports can't be checked.
Related tools
-
Website Down Checker
Check whether a website is responding right now, from our server: status, response time, redirects, IP addresses and HTTPS.
-
Security Header Checker
Check which browser security headers a website sends (HSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) and what they do.
-
Redirect Checker
Follow a web address through every redirect, with the status code, destination and timing of each hop.
-
HTTP Header Checker
See the HTTP status and every response header a website sends, for the final page and each redirect on the way.
-
CAA Checker
See which certificate authorities a domain allows to issue its certificates.
-
DNSSEC Checker
Check whether a domain is signed with DNSSEC and whether validating resolvers accept it.
-
DNS Lookup
Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.
-
MX Lookup
See which mail servers receive email for a domain, in priority order, with each server's addresses.
-
SPF Checker
Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.
-
DMARC Checker
Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.
-
Website Health Check
Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.