SSL check: is your certificate valid?
Enter one or more domains and see the SSL certificate the server presents: whether it is valid, when it expires, who issued it, whether the certificate chain is in order, and which other names it covers.
What the SSL check covers
- Whether there is a certificate
- We connect to the server on port 443 and read the certificate it presents for the name you entered.
- Validity and expiry
- Whether the certificate is valid today, the day it expires and how many days are left. We warn two weeks before expiry.
- Hostname
- Whether the certificate is really issued for the name you entered, wildcard names (*.example.com) included.
- Certificate chain
- Whether the server sends all the intermediate certificates, every signature checks out, and the chain ends in a trusted root.
- Issuer
- Which certificate authority issued the certificate.
- Other names (SAN)
- Every other domain the same certificate is valid for.
Frequently asked questions
What does an incomplete certificate chain mean?
The server sends only its own certificate and not the intermediate certificate that issued it. Browsers often fill the gap themselves, so the site seems to work, but mail servers, mobile apps and programs calling an API reject the connection. The fix is to install the full chain (fullchain) on the server.
Can I check several domains at once?
Yes, up to five, separated by commas or spaces: for example the name with and without www together. You can also give a port, such as mail.example.com:993.
Which ports can it check?
Those where the service speaks TLS from the first byte: 443 (HTTPS), 465 (SMTPS), 993 (IMAPS), 995 (POP3S), 636 (LDAPS), 853 (DNS over TLS) and 8443. Ports that use STARTTLS (25, 587, 143) are not supported.