The OriginalHostChecker

SSL Certificate Checker

Enter a domain to see its SSL/TLS certificate: who issued it, when it expires, and how many days are left. Free, no signup.

Try

What this SSL checker shows

When you run a check, HostChecker connects to the host on port 443, asks for its certificate the same way a browser does (including the server name, so sites that share an IP address return the right one), and reads the certificate the server presents. Here is an example result, with what each part tells you:

Example What a check of example.com could show. Not a live result.
Certificate
Valid
In date. It reads Expired once the end date has passed.
Days left
52
Counted from right now, and amber under 30. This is the number to watch.

Certificate details

Issued to
example.comThe name the certificate was issued for (the subject). It should match the domain you typed.
Issued by
Example Trust Services · Example CA 1The certificate authority (CA) that signed it, such as Let’s Encrypt, DigiCert, Sectigo, or Google Trust Services.
Valid from
2026-09-01The first day browsers accept it. Before this date it is rejected.
Valid to
2026-11-29The last day browsers accept it. After this date visitors get a full-page warning.

This check reads the certificate and its dates. It does not rebuild the full trust chain or confirm that the name matches, which is what a browser does before it shows a padlock. For a browser-style verdict (HTTP status, redirects, and certificate problems at every hop), run Host Check.

How to read the result

Common SSL certificate problems and fixes

The certificate has expired

One of the most common causes of an SSL error. Certificates have a hard end date, and a missed renewal takes the site’s padlock with it. Renew, install the new certificate, and reload the web server. Then re-run this check to confirm the new dates.

The certificate is for a different name

Browsers report this as a name mismatch (NET::ERR_CERT_COMMON_NAME_INVALID in Chrome). The certificate was issued for example.com but is being served for www.example.com, or the other way round. Reissue it with every name you serve (a SAN or wildcard certificate), or point each name at a server that has the right certificate. Compare the “Issued to” field above with the name you typed.

The issuer is not trusted

Self-signed certificates and certificates from an unknown CA show a warning because browsers have no reason to trust them. If “Issued by” names the same site as “Issued to”, the certificate is self-signed. An unknown or private CA can’t be spotted from the names alone, and this check still shows a green “Valid” for either one because it only reads the dates. Host Check reports the trust error browsers would show. The fix is a certificate from a public CA. Let’s Encrypt is free.

The certificate chain is incomplete

Servers must send the intermediate certificate along with their own. When they don’t, some desktop browsers cope by fetching or remembering the missing piece, but Android devices, many apps, and command-line tools fail with “unable to get local issuer certificate”. The fix is to install the full chain file your CA provides, usually called fullchain.pem or the “bundle”.

The wrong certificate is served

Hosts that serve many sites from one IP address pick the certificate by the name you ask for. Checking by raw IP address often returns a default certificate that names a different site. Check by domain name whenever you can.

Frequently asked questions

How do I check when an SSL certificate expires?

Type the domain into the box above and run the check. The result shows the exact expiry date under “Valid to” and the number of days left. You can also click the padlock in a browser’s address bar and open the certificate details, or run openssl s_client -connect example.com:443 -servername example.com and pipe it to openssl x509 -noout -dates.

How long is an SSL certificate valid for?

It depends on the issuer, and the maximum keeps shrinking. Under the industry’s current rules (CA/Browser Forum ballot SC-081), public certificates issued since 15 March 2026 can last at most 200 days. That drops to 100 days on 15 March 2027 and 47 days on 15 March 2029. Let’s Encrypt certificates last 90 days today. It has announced that its default will become 64 days on 10 February 2027 and 45 days on 16 February 2028. Short lifetimes are why automated renewal matters.

Why does this show a valid certificate when my browser still shows a warning?

This check reads the certificate and its dates, but it does not rebuild the trust chain or compare the name to the address you visited. A warning with a certificate that is in date usually means a name mismatch, a missing intermediate certificate, or a certificate your browser has been told to distrust. Run Host Check for the certificate problems browsers actually flag, and see the list above.

Can I check an SSL certificate on a port other than 443?

No. This tool checks the standard HTTPS port, 443. Mail servers, databases, and other services that use their own TLS ports are not covered.

Can I check a certificate by IP address?

Yes, but the result may not be what you expect. Certificates are issued for domain names, so a certificate fetched by IP often names a different site or does not name the IP at all. That is normal. To see what visitors get, check by domain name.

Is the SSL checker free?

Yes. There is no signup, no account, and no limit on how many sites you can check, apart from a per-visitor rate limit that keeps the service fast for everyone.

All free tools

Related reading

SSL Certificate Expired? Here’s How to Fix It FastWhat causes a certificate to expire, how to renew it quickly, and how to stop it happening again.