SSL / TLS Certificate Checker
Inspect X.509 certificates and TLS handshake configuration.
- Runs in your browser
- Free, no signup
Certificate for —
Valid- Common Name (CN)
- —
- Issuer Organization
- —
- Valid From
- —
- Valid Until
- —
- Days Remaining
- —
- TLS Protocol
- —
- Public Key
- —
- Signature Algorithm
- —
- Subject Alternative Names
- —
Certificate Chain
| Level | Subject | Issuer | Expires |
|---|
Connections inspect public X.509 certificates only. No keys or certificates are stored.
An expired or misconfigured SSL/TLS certificate triggers severe browser warnings, destroying visitor trust and blocking access to your website. Regular certificate checks ensure your domains maintain valid encryption and timely renewals.
This tool establishes a direct TLS connection to your server, captures the public X.509 peer certificate, checks expiration countdowns, verifies Subject Alternative Names (SANs), and examines the certificate authority chain.
How to use this tool
- Enter a domain name (e.g., example.com) or hostname.
- Click Check SSL to initiate a TLS handshake.
- Review the validity status, days remaining until expiry, issuer organization, SANs, and certificate chain levels.
Certificate lifespans and automated renewal
Modern public SSL certificates are limited to a maximum validity of 398 days, and automated providers like Let's Encrypt issue 90-day certificates. If an automated ACME cron job fails, certificates can expire without warning.
Our tool alerts you if a certificate has expired, has fewer than 30 days remaining, or fails to match the requested domain name.
Subject Alternative Names (SANs) and wildcards
Modern browsers ignore the legacy Common Name (CN) and rely strictly on Subject Alternative Names (SANs). A single certificate can secure multiple domains (e.g. example.com, www.example.com) or use wildcards (*.example.com).
Our tool tests your domain against all active SAN patterns to confirm complete hostname coverage.
Frequently asked questions
Can this tool inspect non-standard SSL ports?
Yes. You can append a port to the hostname (e.g. example.com:8443) or use the default port 443.
Are private keys exposed during an SSL check?
No. TLS is asymmetric: only the public X.509 certificate is transmitted during the TLS handshake. Private keys always remain secure on your server.