What this SSL checker shows
When you run a check, HostChecker connects to the host on port 443, asks for its certificate the same way a browser does (including the server name, so sites that share an IP address return the right one), and reads the certificate the server presents. Here is an example result, with what each part tells you:
Certificate details
This check reads the certificate and its dates. It does not rebuild the full trust chain or confirm that the name matches, which is what a browser does before it shows a padlock. For a browser-style verdict (HTTP status, redirects, and certificate problems at every hop), run Host Check.
How to read the result
- 30 or more days left (green). The dates are fine. Green says nothing about whether browsers trust the certificate (see below). Automated renewal usually kicks in when about a third of the certificate’s life is left, which is 30 days for a 90-day certificate, so a certificate that is part-way through its life is usually just a renewal cycle working.
- Under 30 days left (amber). Renew soon. For a 90-day certificate that is set to renew automatically, still being under 30 days usually means the renewal job is failing, so fix it now, not on the last day. Certificates are getting shorter-lived (see the FAQ), and a certificate that lasts 64 days or less will normally spend part of every cycle in amber. Compare “Valid from” and “Valid to” to see how long this certificate lasts in total.
- Expired (red). Visitors get a full-page browser warning, and many will turn back. Renew or reissue the certificate and reload the web server so it serves the new one. Our guide, SSL certificate expired: how to fix it fast, walks through it.
- Not found. Nothing answered with a certificate on port 443. The site may not use HTTPS, the name may not point to the right server, a firewall may block 443, or the host is down. Try Ping and DNS Lookup to narrow it down.
Common SSL certificate problems and fixes
The certificate has expired
One of the most common causes of an SSL error. Certificates have a hard end date, and a missed renewal takes the site’s padlock with it. Renew, install the new certificate, and reload the web server. Then re-run this check to confirm the new dates.
The certificate is for a different name
Browsers report this as a name mismatch (NET::ERR_CERT_COMMON_NAME_INVALID in Chrome). The certificate was issued for example.com but is being served for www.example.com, or the other way round. Reissue it with every name you serve (a SAN or wildcard certificate), or point each name at a server that has the right certificate. Compare the “Issued to” field above with the name you typed.
The issuer is not trusted
Self-signed certificates and certificates from an unknown CA show a warning because browsers have no reason to trust them. If “Issued by” names the same site as “Issued to”, the certificate is self-signed. An unknown or private CA can’t be spotted from the names alone, and this check still shows a green “Valid” for either one because it only reads the dates. Host Check reports the trust error browsers would show. The fix is a certificate from a public CA. Let’s Encrypt is free.
The certificate chain is incomplete
Servers must send the intermediate certificate along with their own. When they don’t, some desktop browsers cope by fetching or remembering the missing piece, but Android devices, many apps, and command-line tools fail with “unable to get local issuer certificate”. The fix is to install the full chain file your CA provides, usually called fullchain.pem or the “bundle”.
The wrong certificate is served
Hosts that serve many sites from one IP address pick the certificate by the name you ask for. Checking by raw IP address often returns a default certificate that names a different site. Check by domain name whenever you can.
Frequently asked questions
How do I check when an SSL certificate expires?
Type the domain into the box above and run the check. The result shows the exact expiry date under “Valid to” and the number of days left. You can also click the padlock in a browser’s address bar and open the certificate details, or run openssl s_client -connect example.com:443 -servername example.com and pipe it to openssl x509 -noout -dates.
How long is an SSL certificate valid for?
It depends on the issuer, and the maximum keeps shrinking. Under the industry’s current rules (CA/Browser Forum ballot SC-081), public certificates issued since 15 March 2026 can last at most 200 days. That drops to 100 days on 15 March 2027 and 47 days on 15 March 2029. Let’s Encrypt certificates last 90 days today. It has announced that its default will become 64 days on 10 February 2027 and 45 days on 16 February 2028. Short lifetimes are why automated renewal matters.
Why does this show a valid certificate when my browser still shows a warning?
This check reads the certificate and its dates, but it does not rebuild the trust chain or compare the name to the address you visited. A warning with a certificate that is in date usually means a name mismatch, a missing intermediate certificate, or a certificate your browser has been told to distrust. Run Host Check for the certificate problems browsers actually flag, and see the list above.
Can I check an SSL certificate on a port other than 443?
No. This tool checks the standard HTTPS port, 443. Mail servers, databases, and other services that use their own TLS ports are not covered.
Can I check a certificate by IP address?
Yes, but the result may not be what you expect. Certificates are issued for domain names, so a certificate fetched by IP often names a different site or does not name the IP at all. That is normal. To see what visitors get, check by domain name.
Is the SSL checker free?
Yes. There is no signup, no account, and no limit on how many sites you can check, apart from a per-visitor rate limit that keeps the service fast for everyone.