Free SSL Certificate Checker

Instantly check any domain's SSL certificate — validity, expiry date, issuer, TLS version, and certificate chain. No account needed.

What This SSL Checker Verifies

Certificate Validity
Verifies the certificate is currently valid and issued by a trusted Certificate Authority.
Expiry Date
Shows the exact expiry date and how many days remain before the certificate expires.
TLS Version
Identifies the TLS version negotiated — TLS 1.3, 1.2, or older (deprecated) versions.
Certificate Chain
Checks that intermediate certificates are properly installed and the chain is complete.
Issuer & Subject
Shows the Certificate Authority that issued the certificate and the domain it is valid for.
Expiry Warnings
Highlights when certificates are within 7, 14, or 30 days of expiry.

Frequently Asked Questions

What does an SSL checker verify?

An SSL checker verifies that a domain's SSL/TLS certificate is valid, not expired, issued by a trusted Certificate Authority, and that the certificate chain is properly configured. It also checks the TLS version, expiry date, and issuer details.

How often should I check my SSL certificate?

We recommend checking weekly for critical production domains and daily if you are within 30 days of expiry. Automated monitoring (like CertNotify) handles this for you — sending alerts at 30, 14, and 7 days before expiry.

What is a certificate chain and why does it matter?

A certificate chain is the sequence of certificates from your domain's certificate up to a trusted root CA. If any intermediate certificate is missing or misconfigured, browsers will display security warnings even if your end certificate is valid.

What does the SSL grade mean?

The grade represents the overall security quality of the SSL/TLS configuration: A+ = excellent (HSTS preloaded), A = strong, B = acceptable but room for improvement, C/D/F = significant issues that need attention.

Can I check SSL for any domain, including internal or staging servers?

Our checker works for any publicly accessible domain or IP address. For internal or private servers, you would need to run a local tool like openssl or a self-hosted scanner.

What does "certificate not trusted" mean?

This means the certificate was issued by a CA that is not in the browser or OS trusted root store, the certificate is self-signed, or the certificate chain is incomplete. Users will see a security warning in their browser.

Get Alerted Before Your SSL Expires

CertNotify monitors your SSL certificates and sends alerts 30, 14, and 7 days before expiry — before browsers show warnings to your visitors.

Related Free Tools