SPF, DKIM and DMARC check
SPF, DKIM and DMARC for your domain: what is missing, what is wrong and the exact record that fixes it.
FREE TOOL
When the certificate expires, who issued it, whether the chain is complete and whether http redirects to https. With a calendar reminder and no sign-up.
issuer, names, dates, key and signature
whether it leads to a trusted root
the TLS version
whether http redirects to https
the Strict-Transport-Security header
which certificate authorities may issue
What it means:
What to do:
Two dates in your calendar, 14 and 3 days before expiry, each with an alert at 9:00. The file is made in your browser: we keep no e-mail and send no messages.
Only the reminder 3 days before expiry is left; it is too late for the other.
Let's Encrypt certificates last 90 days, and the maximum life of every public certificate drops to 200 days from March 2026.
Replace your text with the result?
A copy is on its way to your inbox. If it does not arrive, check the spam folder — and write to us directly. [email protected]
Reference number:
We open a secure connection to the site on port 443 and read the certificate: issuer, names, dates, key and signature. A second connection checks the chain against the trusted roots, as a browser does. Then we request the home page over http and over https, for the redirect and the HSTS header, and ask public DNS for a CAA record. The result is kept for 10 minutes under a key the address cannot be read from.
We only look at what the site shows every visitor and at the domain's public records. We do not try passwords, forms or hidden addresses.
We watch the certificate and the domain every week as part of website maintenance.
What an SSL certificate is, in the glossary: SSL certificate
QUESTIONS
Type the domain above: the first row shows the expiry date and how many days are left. A browser shows the same in the certificate details behind the icon next to the address. So that it does not slip by, add a reminder to your calendar with the button under the result.
Usually for one of four reasons: the certificate has expired, it was issued for another name, an intermediate certificate is missing, or the page opens over plain http. The check above shows which one it is.
A browser trusts your certificate because an intermediate certificate signed it, and a root the browser knows signed the intermediate. The server has to send the intermediate too. When it does not, browsers that find it themselves open the site and others, often on phones and in apps, refuse. That is why the fault only shows sometimes.
Let's Encrypt certificates last 90 days for now. A public certificate issued on or after 15 March 2026 is valid for at most 200 days; one issued from 15 March 2027, 100 days; and from 15 March 2029, 47 days. That is why renewal has to be automatic.
A header with which a site tells the browser to open it over https only. After the first visit the browser swaps http for https itself, before it sends a request. Six months or more is recommended (max-age=15768000); includeSubDomains and preload widen the rule.
Because we keep no e-mail addresses. The "Add a reminder to your calendar" button makes a file in your browser with two reminders, 14 and 3 days before expiry. It opens in Google Calendar, Outlook and Apple Calendar, and nobody but you knows about it.
SPF, DKIM and DMARC for your domain: what is missing, what is wrong and the exact record that fixes it.
Which registrar holds the domain, where the site is hosted and who runs the mail.