# SSL certificate check

> When the certificate expires, who issued it, whether the chain is complete and whether http redirects to https. With a calendar reminder and no sign-up.

## What we check

We open a secure connection to the site on port 443 and read the certificate: issuer, names, dates, key and signature. A second connection checks the chain against the trusted roots, as a browser does. Then we request the home page over http and over https, for the redirect and the HSTS header, and ask public DNS for a CAA record. The result is kept for 10 minutes under a key the address cannot be read from.

## What people ask

### How do I check when an SSL certificate expires?

Type the domain above: the first row shows the expiry date and how many days are left. A browser shows the same in the certificate details behind the icon next to the address. So that it does not slip by, add a reminder to your calendar with the button under the result.

### Why does the browser say the connection is not secure?

Usually for one of four reasons: the certificate has expired, it was issued for another name, an intermediate certificate is missing, or the page opens over plain http. The check above shows which one it is.

### What is an incomplete certificate chain?

A browser trusts your certificate because an intermediate certificate signed it, and a root the browser knows signed the intermediate. The server has to send the intermediate too. When it does not, browsers that find it themselves open the site and others, often on phones and in apps, refuse. That is why the fault only shows sometimes.

### How long is an SSL certificate valid?

Let's Encrypt certificates last 90 days for now. A public certificate issued on or after 15 March 2026 is valid for at most 200 days; one issued from 15 March 2027, 100 days; and from 15 March 2029, 47 days. That is why renewal has to be automatic.

### What is HSTS?

A header with which a site tells the browser to open it over https only. After the first visit the browser swaps http for https itself, before it sends a request. Six months or more is recommended (max-age=15768000); includeSubDomains and preload widen the rule.

### Why don't you e-mail me before it expires?

Because we keep no e-mail addresses. The "Add a reminder to your calendar" button makes a file in your browser with two reminders, 14 and 3 days before expiry. It opens in Google Calendar, Outlook and Apple Calendar, and nobody but you knows about it.

Page: https://tnb-tech.com/en/ssl-certificate-check/
