SSL Certificate Check
Analyze your website SSL/TLS certificate status, validity period, and chain structure in detail.
Security Analysis
Check your SSL/TLS certificate validity, chain structure, and security configuration in detail.
Time Tracking
Track when your certificate expires. Renew before expiration to ensure uninterrupted security.
Chain Validation
Verify that your certificate chain is properly configured and all intermediate certificates are present.
What is an SSL/TLS certificate?
An SSL/TLS certificate encrypts the connection between the browser and the website and proves that the site really belongs to that domain. For https and the padlock to appear in the address bar, the site must use a valid, unexpired certificate signed by a trusted certificate authority.
The tool connects to port 443 of the domain and shows the certificate's validity, expiry date and days remaining, the issuer, the domains it covers (SAN), the certificate chain, the TLS version and the cipher. It warns you when 30 days or fewer are left before expiry.
How to use
- 1Enter the domain without https:// (for example example.com).
- 2Press Check.
- 3Review the days remaining, the chain and any warnings; if an intermediate certificate is missing from the chain, add it on your server.
Frequently asked questions
What is a certificate chain?
Your site's certificate is linked to a root certificate trusted by browsers through one or more intermediate certificates. If the server does not send the intermediate certificate, some browsers and apps treat the connection as untrusted, so the intermediate certificates (fullchain) must be installed on the server together with the certificate.
What happens when a certificate expires?
Visitors see a security warning such as “Your connection is not private” and most leave without entering the site; API and email connections start failing as well. Even with automatically renewed certificates, you should check regularly that renewal works.
What is a SAN (Subject Alternative Name)?
The SAN is the list of domain names a certificate is valid for. Browsers look for the domain in this list; for example, a certificate whose SAN list only contains www.example.com shows an error on example.com without www.
What is the difference between TLS 1.2 and TLS 1.3?
TLS 1.3 sets up connections in fewer steps, which makes it faster, and removes old and weak ciphers entirely. TLS 1.2 is still considered secure. TLS 1.0 and 1.1 are no longer supported by browsers.
How early should I renew a certificate?
Renewing at least 30 days before expiry leaves time for validation and installation delays; the tool also warns you once you are within that window. Let's Encrypt certificates are valid for 90 days and are usually renewed automatically 30 days before expiry.