SSL Certificate Checker

37 tools

Read the certificate a host presents over TLS.

Free to use with no account. JSON, passwords, hashes, 2FA and text tools run entirely in your browser.

SSL Certificate Checker

Read the certificate a host presents over TLS.

Free

About

Enter a hostname and our server completes a TLS handshake with it, then reports the certificate that came back. Subject, issuer, and the validity window are the fields most people are here for, and expiry is usually the one that prompted the visit.

How to use

Enter the hostname alone, without https:// and without a path. Certificates are selected by hostname, so an IP address will usually return the wrong one or none at all.

What the handshake hands over

Before any HTTP request happens, the server presents a certificate. It carries the names it is valid for, who issued it, and the window in which it is valid. That exchange is public by design, which is why reading it requires no permission and no login. Everything shown here is what any client sees on connecting.

Expiry, and the week before it

Most certificates now renew automatically and most of the time that works. The failures are quiet: a renewal hook that stopped running, a certificate renewed on disk but never loaded by the running process, or a load balancer holding an older copy than the origin. Checking the served date rather than the issued date is what distinguishes those, and it is the reason to look from outside.

Which names a certificate covers

A certificate lists every name it is valid for, and that list is often longer than the site you typed. A wildcard entry covers one level of subdomain and no more, which is why an apex domain can fail while everything beneath it works. When a client reports a name mismatch, this list settles it in a few seconds.

What this does not assess

Protocol versions, cipher strength, chain configuration problems, and revocation status are all outside what is shown here. A certificate can be present, in date, and correctly named while the server still negotiates something it should not. For that level of detail, use a scanner built for grading configurations rather than a field reader.

FAQ

The certificate expired. Will the site stop working?

Browsers will interrupt visitors with a warning that most will not click through. Some scripts and older clients will carry on regardless, which is why an expiry can go unnoticed until a customer reports it.

Do I get a security grade out of this?

No. This reads certificate fields. Grading a TLS configuration means testing cipher suites and protocol versions, which is a different and much slower kind of scan.

Why do I need the hostname rather than the IP?

One address commonly hosts many sites, and the server picks a certificate from the name the client asked for. Without a name there is nothing to select on.

The name in the certificate does not match the site. Is that bad?

It is worth understanding rather than panicking about. Certificates cover several names at once, and a shared or CDN certificate can look wrong while being entirely correct for that host.

Related tools

SSL Certificate Checker - Issuer, Expiry and Names