Free tool

Free SSL Certificate Checker

Check the TLS certificate a hostname serves on port 443. You get days left until expiry, the issuer, the names on the certificate (SAN), and the chain the server presented. The hostname you enter is not stored.

One hostname, such as www.example.com. We check port 443 only. A pasted URL is fine; we keep just the hostname.

The hostname is not stored. The result is shown once, in this page only.

What this check tells you

This tool connects to one hostname on port 443, reads the certificate the server presents, and reports what it found at that moment.

  • Days left is the time from this check until the certificate's expiry date. If it can't be read, you'll see unknown.
  • SAN lists every name the certificate covers. If your hostname isn't on that list, browsers will warn visitors even when the certificate is in date.
  • The chain shows the certificates the server sent. A missing intermediate is a common cause of errors on some devices but not others.
  • Missing intermediates are not fetched. This checker judges only the chain the server sends. It does not download missing intermediate certificates (no AIA fetching), so a missing intermediate shows as CHAIN_INCOMPLETE even where some browsers recover by fetching it themselves.

What it doesn't do

It checks one hostname, once. It doesn't watch the certificate over time, renew anything, look up domain registration, or tell you whether the site is up. The hostname you enter is not stored.

For background, read how to read an SSL certificate expiry check and the difference between domain expiry and SSL expiry.

Checking more than one site?

A one-off check is a snapshot. Domainvane's monitoring re-checks a list of hostnames about every 24 hours for TLS certificate expiry and domain-registration expiry (from RDAP), and shows the status on one dashboard. The free plan covers 3 domains, no card required.