How to check when an SSL certificate expires
Every TLS certificate (still usually called an SSL certificate) has an end date. After that moment, browsers stop trusting it and visitors see a full-page warning instead of the site. Checking that date takes a few seconds. Knowing what the result actually tells you takes a little more.
This guide covers what "expiry" means on a certificate, how to check it, how to read the result, and where a one-off check stops being enough.
What certificate expiry means
A certificate carries two dates: not before (when it starts being valid) and not after (when it stops). The expiry date is the not-after time. It is set when the certificate is issued and does not change. Renewing a certificate does not extend the old one; it replaces it with a new certificate that has new dates.
That matters for checking. The question is never "when does this domain's certificate expire?" in the abstract. It is "what certificate is this hostname serving right now, and when does that one expire?" If a renewal happened but the server is still presenting the old certificate, the old date is the one visitors run into.
Days left is simply the time between the moment you check and the certificate's not-after date. A good check shows it as a whole number of days and shows the exact expiry date and time next to it, so there is no rounding confusion near the end.
If a check can't read the certificate (the name doesn't resolve, the server refuses the connection, the TLS handshake fails), the honest answer is unknown. A tool should never fill that gap with a guess.
Why it is worth checking more often than you used to
Certificate lifetimes are getting shorter. The CA/Browser Forum, which sets the rules publicly trusted certificate authorities follow, adopted Ballot SC-081v3 in 2025. It caps the validity of publicly trusted TLS certificates at 200 days for certificates issued from 15 March 2026, 100 days from 15 March 2027, and 47 days from 15 March 2029. Many certificates are already issued with much shorter lifetimes than the maximum.
Shorter lifetimes mean more renewals, and each renewal is another chance for automation to fail without anyone noticing.
How to check a certificate's expiry
In a browser
Open the site, click the padlock or site-information icon in the address bar, and open the certificate details. You'll see the issuer, the validity dates, and the names the certificate covers. This works, but it is slow for more than one site, and the browser may show a cached connection rather than a fresh one.
On the command line
If you're comfortable in a terminal, OpenSSL can connect and print the dates:
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -dates -issuer -subject
The -servername flag matters. Many servers host several sites on one IP address and pick the certificate based on the name you ask for. Leave it out and you may read the wrong certificate.
With a checker
Our free SSL certificate checker connects to one hostname on port 443 and shows days left, the expiry date, the issuer, the names on the certificate (SAN), and the chain the server presented. It also gives you a plain-text diagnostic you can copy into a ticket or a message to a client. The hostname you enter is not stored.
How to read the result
Days left and expiry date. The headline number. If it is low, find out how this certificate is supposed to renew (an ACME client such as Certbot, your host's control panel, a CDN, a manual purchase) and confirm that process is still working.
Issuer. The certificate authority that signed the certificate. If the issuer isn't what you expected, someone may have moved the site behind a CDN or a different host, and renewal may now be handled somewhere you don't control.
Names on the certificate (SAN). Subject alternative names list every hostname the certificate covers. If the name you checked isn't on the list, browsers will warn visitors even though the certificate is in date. A common case: the certificate covers example.com but not www.example.com, or the other way round. A wildcard such as *.example.com covers one level of subdomain only.
Chain. Servers should send their own certificate plus any intermediate certificates needed to link it to a trusted root. If an intermediate is missing, some browsers and devices cope and others fail. That is why "it works on my machine" is a classic chain problem. The chain view shows what the server actually sent.
Unknown. Treat unknown as a reason to look closer, not as a pass. It means the check couldn't establish that value.
What a one-off check can't tell you
A single check describes the certificate it saw at that moment. It does not:
- tell you whether the site is up or working,
- renew anything,
- tell you when the domain name itself expires,
- or keep watching after you close the tab.
The domain point trips people up. A certificate and a domain registration are separate things with separate dates, renewed by different companies. A valid certificate on a domain whose registration has lapsed is not much use. We cover the difference in domain expiry and SSL expiry.
When to move from checking to monitoring
Checking by hand works for one or two sites you look at often. It breaks down when you're responsible for many hostnames, especially ones belonging to clients, where a lapse is noticed by their customers first.
At that point the job changes from "check this certificate" to "keep a list of hostnames and see which ones need attention." That list needs to be re-checked on a schedule, cover both certificate expiry and domain-registration expiry, and show everything in one place.
That is what Domainvane does. It re-checks each hostname you add about every 24 hours (more often when a certificate is within 7 days of expiry or a check is failing), reads the certificate on port 443, and looks up domain-registration expiry through RDAP. If RDAP doesn't return a clear date, the result stays unknown. Domainvane does not fall back to WHOIS or guess. Status shows on your dashboard, flagged at 30, 14, 7, and 1 days before expiry. Email alerts are delivered to external inboxes, including Gmail. Inbox placement is not guaranteed for every provider (Outlook and Yahoo have not been tested).
Domainvane is not an uptime monitor. It watches expiry and certificate problems, not whether pages load.
If you look after client sites, read SSL certificate monitoring for agencies. The free plan covers 3 domains; see plans and limits for the rest.
Quick checklist
- Check the hostname visitors actually use, including
wwwif they use it. - Confirm days left and the exact expiry date.
- Confirm the hostname appears in the SAN list.
- Look at the chain for a missing intermediate.
- Know how this certificate renews and who owns that process.
- Check the domain registration separately.
Run a check on one hostname now. The hostname is not stored.