FREE TOOL

SSL certificate check

When the certificate expires, who issued it, whether the chain is complete and whether http redirects to https. With a calendar reminder and no sign-up.

We check the name and its www. form.

We open a secure connection to the site, as your browser does, and read the certificate it shows everyone. The reminder is a calendar file made in your browser: we keep no e-mail and send no messages.

Result

Certificate

issuer, names, dates, key and signature

—
Chain

whether it leads to a trusted root

—
Protocol

the TLS version

—
http → https

whether http redirects to https

—
HSTS

the Strict-Transport-Security header

—
CAA

which certificate authorities may issue

—

What this means

Calendar reminder

Two dates in your calendar, 14 and 3 days before expiry, each with an alert at 9:00. The file is made in your browser: we keep no e-mail and send no messages.

Only the reminder 3 days before expiry is left; it is too late for the other.

Let's Encrypt certificates last 90 days, and the maximum life of every public certificate drops to 200 days from March 2026.

WANT A HAND

Send us the result

Replace your text with the result?

ENQUIRY RECEIVED

We have it. We reply within two working days.

A copy is on its way to your inbox. If it does not arrive, check the spam folder — and write to us directly. [email protected]

Reference number:

Which layer hurts?

Pick the service you need — the small mark beside it is our name for that layer in the story.

The text below comes from your result. Read it, change it or delete any of it. Nothing is sent until you press Send.

A brief, a screenshot or a sketch. Up to 8 MB.

Picked: Care & security

We use what you write only to answer you. See the privacy policy.

What we check

We open a secure connection to the site on port 443 and read the certificate: issuer, names, dates, key and signature. A second connection checks the chain against the trusted roots, as a browser does. Then we request the home page over http and over https, for the redirect and the HSTS header, and ask public DNS for a CAA record. The result is kept for 10 minutes under a key the address cannot be read from.

We only look at what the site shows every visitor and at the domain's public records. We do not try passwords, forms or hidden addresses.

We watch the certificate and the domain every week as part of website maintenance.

What an SSL certificate is, in the glossary: SSL certificate

QUESTIONS

What people ask

How do I check when an SSL certificate expires?

Type the domain above: the first row shows the expiry date and how many days are left. A browser shows the same in the certificate details behind the icon next to the address. So that it does not slip by, add a reminder to your calendar with the button under the result.

Why does the browser say the connection is not secure?

Usually for one of four reasons: the certificate has expired, it was issued for another name, an intermediate certificate is missing, or the page opens over plain http. The check above shows which one it is.

What is an incomplete certificate chain?

A browser trusts your certificate because an intermediate certificate signed it, and a root the browser knows signed the intermediate. The server has to send the intermediate too. When it does not, browsers that find it themselves open the site and others, often on phones and in apps, refuse. That is why the fault only shows sometimes.

How long is an SSL certificate valid?

Let's Encrypt certificates last 90 days for now. A public certificate issued on or after 15 March 2026 is valid for at most 200 days; one issued from 15 March 2027, 100 days; and from 15 March 2029, 47 days. That is why renewal has to be automatic.

What is HSTS?

A header with which a site tells the browser to open it over https only. After the first visit the browser swaps http for https itself, before it sends a request. Six months or more is recommended (max-age=15768000); includeSubDomains and preload widen the rule.

Why don't you e-mail me before it expires?

Because we keep no e-mail addresses. The "Add a reminder to your calendar" button makes a file in your browser with two reminders, 14 and 3 days before expiry. It opens in Google Calendar, Outlook and Apple Calendar, and nobody but you knows about it.

All tools
via public DNS

SPF, DKIM and DMARC check

SPF, DKIM and DMARC for your domain: what is missing, what is wrong and the exact record that fixes it.

SPF, DKIM and DMARC check
on our server

Who hosts this website

Which registrar holds the domain, where the site is hosted and who runs the mail.

Who hosts this website