Free tool
Free SSL Certificate Checker
Check the TLS certificate a hostname serves on port 443. You get days left until expiry, the issuer, the names on the certificate (SAN), and the chain the server presented. The hostname you enter is not stored.
What this check tells you
This tool connects to one hostname on port 443, reads the certificate the server presents, and reports what it found at that moment.
- Days left is the time from this check until the certificate's expiry date. If it can't be read, you'll see unknown.
- SAN lists every name the certificate covers. If your hostname isn't on that list, browsers will warn visitors even when the certificate is in date.
- The chain shows the certificates the server sent. A missing intermediate is a common cause of errors on some devices but not others.
- Missing intermediates are not fetched. This checker judges only the chain the server sends. It does not download missing intermediate certificates (no AIA fetching), so a missing intermediate shows as
CHAIN_INCOMPLETEeven where some browsers recover by fetching it themselves.
What it doesn't do
It checks one hostname, once. It doesn't watch the certificate over time, renew anything, look up domain registration, or tell you whether the site is up. The hostname you enter is not stored.
For background, read how to read an SSL certificate expiry check and the difference between domain expiry and SSL expiry.
Checking more than one site?
A one-off check is a snapshot. Domainvane's monitoring re-checks a list of hostnames about every 24 hours for TLS certificate expiry and domain-registration expiry (from RDAP), and shows the status on one dashboard. The free plan covers 3 domains, no card required.