Free tool
SSL/TLS Checker
Certificate validity, expiry date and the configuration behind it.
How it works
What is the SSL/TLS Checker?
The SSL/TLS Checker is a free tool that connects to a website on port 443 and inspects the certificate it presents. It reports whether the certificate is trusted and in date, how many days remain, whether it covers the hostname, the TLS version and cipher negotiated, and which security headers the site sends, with a score out of 100.
How to use the SSL/TLS Checker
- Enter the domain, such as example.com or shop.example.com. The check covers the hostname you type.
- Press Check SSL.
- Read the certificate card: who it was issued to and by, the valid-from and expiry dates, days left, the cipher and the hostnames it covers.
- Check the security score and the risk assessment, which lists each issue found: an untrusted certificate, a hostname it does not cover, an old TLS version, expiry within 30 days or a missing security header.
- Scroll to the security headers, the server's IP address and the TLS protocol it negotiated.
How do I check if an SSL certificate is valid?
An SSL certificate is valid when three things are true: it is in date, it chains to a trusted root, and the hostname appears in its Subject Alternative Name (SAN) list. They are separate checks, and a certificate can pass two and fail the third.
The hostname check is the one people miss. A certificate from a real CA, correctly signed and in date, still triggers a browser error if it covers example.com and the visitor asked for shop.example.com. Browsers match the hostname against SAN entries, not the Common Name, and this checker does the same.
Does a wildcard SSL certificate cover the root domain?
No. *.example.com covers www.example.com and shop.example.com, but not example.com itself and not api.v2.example.com. A wildcard stands in for exactly one label.
If the bare domain needs HTTPS, it has to be listed as its own SAN entry. When a renewed wildcard certificate breaks only the root domain, this is almost always why.
Why is my SSL certificate not trusted?
An SSL certificate is usually not trusted because it has expired, it does not cover the hostname, or the server sends it without its intermediate certificate. The first two show up everywhere. The third is intermittent.
When the intermediate is missing, some browsers still connect because they already have it cached or fetch it themselves, while fresh devices, command-line tools and webhooks fail. This checker validates the chain the server actually sends, so a missing intermediate shows up here as an untrusted certificate. If HTTPS works on your laptop and fails in one integration, check the chain first.
Questions
- Are SSL and TLS the same thing?
- No, TLS is the successor to SSL. Every version of SSL is deprecated, and secure connections today use TLS 1.2 or TLS 1.3. The old name stuck, so an "SSL certificate" is the same certificate used for TLS.
- How long does an SSL certificate last?
- An SSL certificate lasts until the expiry date written into it, and the maximum keeps shrinking: public certificates issued since March 2026 can last at most 200 days, falling to 47 days by 2029. Let's Encrypt certificates last 90 days. Automate renewal, and watch the days-left figure this checker shows.
- Does SSL affect SEO?
- Yes, a little. HTTPS has been a lightweight Google ranking signal since 2014. The larger effect is on visitors: browsers mark HTTP pages as not secure and put a full-page warning in front of sites with expired or mismatched certificates.
- Is an SSL certificate free?
- Yes, domain-validated SSL certificates are free from CAs such as Let's Encrypt, and many hosts install one automatically. Paid certificates use the same encryption; the money buys organisation validation, support and warranty terms.
- Which TLS version should my website use?
- Your website should use TLS 1.2 or TLS 1.3. TLS 1.0 and 1.1 were formally deprecated in 2021 and major browsers no longer connect with them, so this checker flags them as insecure. The report shows the version your server actually negotiated.
- Is an SSL certificate necessary for a website?
- Yes, every website needs an SSL certificate, including one with no logins or payments. Browsers mark HTTP pages as not secure, and browser features such as service workers and geolocation work only over HTTPS.
Technical SEO Tools
More in Technical SEO Tools
Opengraph Viewer
Paste a URL and see the card it produces when someone shares it — title, description, image.
View OpengraphOpen Graph Generator
Write the Open Graph tags, preview the card, copy the markup.
Generate Open Graph tagsRobots.txt Checker
Fetch any site's robots.txt and test one URL against it: allowed, or blocked by which rule.
View robots.txtReady when you are
Before your next buyer asks AI about you, ask AI about yourself
One check, four engines, about twenty seconds. We show you the answers before we ask for anything.
