How to use the SSL Certificate Checker
- Enter a domain (e.g. example.com) or full URL and press "Check".
- The top shows days remaining, trust, hostname match and TLS version.
- "Certificate" lists the issuer, validity period and covered domains.
- Fewer than 30 days remaining shows yellow; fewer than 14 days or expired shows red.
Examples
Check a Let's Encrypt certificate
Result from October 3, 2026. Let's Encrypt certificates last 90 days, so the count changes over time.
otaku-dojo.com
Days remaining: 31
Issuer: Let's Encrypt · YR1
Trusted: yes | Hostname: match | TLSv1.3
Domains: otaku-dojo.com, www.otaku-dojo.com
What to do when a certificate is about to expire
Let's Encrypt certificates last 90 days and are usually renewed automatically by tools such as certbot about 30 days before expiry. If fewer than 30 days remain and nothing has changed, automatic renewal has probably failed — check your server's scheduler and firewall. Commercial certificates must be renewed with your vendor and reinstalled.
"Hostname mismatch" means the certificate does not cover the domain you entered — for example it covers example.com but you connected to www.example.com. Reissue a certificate covering every domain or use a wildcard certificate (*.example.com).
Specs & key facts
| Checks | Days remaining, validity period, issuer, subject, SAN list, TLS version |
|---|---|
| Verification | Certificate chain and hostname against trusted CAs |
| Untrusted certificates | Still read, with the failure reason (self-signed, expired, incomplete chain) |
| Ports | 443 by default; enter example.com:8443 for 8443 |
| Limits | Public URLs only, 20 checks per minute |
| Price | Free, no sign-up |
FAQ
My browser says the site is secure but the tool says untrusted. Why?
Usually the server is not sending the full intermediate certificate chain. Browsers may fill the gap from cache, but other clients and some phones fail. Configure your server with the full chain certificate.
What is the difference between SSL and TLS?
TLS is the successor to SSL; SSL 3.0 and TLS 1.0/1.1 are deprecated. "SSL certificate" is still the common name, but sites should use TLS 1.2 or 1.3.
Can I check ports other than 443?
Ports 443 and 8443 are supported — enter example.com:8443. Other ports are blocked for security.