SSL Checker
Enter a host name to see when its SSL/TLS certificate expires, who issued it, which names it covers and whether the chain is complete. The ToolCMB server connects to the host and reads the certificate it presents.
- Valid and trusted?
- Days until expiry
- Certificate chain
- Checked by our server
A browser cannot read the certificate details of another website, so the ToolCMB server connects to the host you enter and reads the certificate it presents. Only the host name is sent — we do not store it or the result.
Enter a domain such as example.com. Add a port for mail or other services, for example mail.example.com:993.
Result
What we found
Certificate details
Certificate chain
The certificates the server sends, from the site certificate up to the issuing authority.
Connection and protocols
TLS 1.2 and 1.3 are current. The old versions 1.0 and 1.1 should be switched off; their test is best effort, because modern software may refuse to offer them.
How to check an SSL certificate
A host name is enough.
- 1
Enter the host name
Type a domain such as example.com. It is sent to the ToolCMB server, which opens a TLS connection to that host — a browser cannot read the certificate details of another website.
- 2
Add a port if needed
Port 443 is used by default. For a mail server or another service, add the port after a colon, for example mail.example.com:993.
- 3
Read the verdict
The result says whether the certificate is valid and trusted and how many days are left, followed by the findings, the certificate details, the chain and the TLS versions the server accepts.
Everything the certificate says
From the expiry date to the last certificate in the chain.
Expiry at a glance
Days left, the exact end date in your time zone and a warning when fewer than 30 days remain. One click downloads a calendar file with a reminder two weeks before the certificate runs out.
Name match
The tool checks whether the certificate covers the host you entered and lists every name it is valid for, including wildcard entries.
Chain and trust
Each certificate the server sends is shown in order: site certificate, intermediates, root. The tool checks that they sign each other and that the chain leads to an authority our server trusts.
TLS versions
See which of TLS 1.3, 1.2, 1.1 and 1.0 the server accepts, plus the protocol and cipher suite of the connection. The test for the two old versions is best effort.
Key and signature
Key type and size (RSA or elliptic curve), signature algorithm, serial number and the SHA-256 and SHA-1 fingerprints, each with a copy button. Weak keys and signatures are flagged.
Issuer and extras
Issuing authority, organization, validity period, and whether the certificate carries Certificate Transparency timestamps and an OCSP address.
Honest about what is sent
The check runs on our server because a browser is not allowed to do it. Only the address you enter is sent; it is not stored.
Protected against abuse
Only public addresses can be checked, and the number of checks per minute is limited so the tool cannot be misused against other sites.
What an SSL certificate check tells you
An SSL certificate — strictly speaking a TLS certificate — does two jobs: it lets a browser encrypt the connection, and it proves that the server belongs to the name in the address bar. For that proof to hold, four things must be true. The certificate must be within its validity period, it must list the host name, it must be signed by a certificate authority that browsers trust, and the server must send the intermediate certificates that connect it to that authority. If one of them fails, visitors see a full-page warning instead of your site.
Our server resolves the host name, connects to the port and performs a TLS handshake with the name you entered (SNI). It parses the certificates the server presents and reports their fields; nothing is stored. Trust is judged against the list of certificate authorities installed on our server, which is close to, but not identical with, the lists used by browsers. The protocol test opens one short connection per TLS version. The tool does not check whether a certificate has been revoked, and it talks to services that start TLS immediately — it does not perform STARTTLS, as used on mail ports 25 and 587.
The most frequent fault is simply an expired certificate, usually because automatic renewal stopped working unnoticed. Next comes the missing intermediate: the site works in desktop browsers that have cached it, yet fails on other devices and in API clients. Install the full chain file, not only the site certificate. A name mismatch typically means the certificate covers www.example.com and not example.com, or the other way round. Lifetimes are also getting shorter: since March 2026, newly issued public certificates may be valid for 200 days at most, and the limit drops to 47 days by 2029, so automated renewal is the only practical approach.
Common certificate problems
| Problem | What visitors see | Fix |
|---|---|---|
| Expired certificate | Full-page warning in every browser | Renew it and repair the automatic renewal |
| Name mismatch | Warning that the certificate is for another site | Reissue the certificate with all host names, with and without www |
| Missing intermediate | Works on some devices, fails on others | Install the full chain file on the server |
| Self-signed or untrusted issuer | Warning that the issuer is unknown | Use a certificate from a publicly trusted authority |
| TLS 1.0 / 1.1 still accepted | Nothing — but security scans fail | Switch the old versions off in the server configuration |
Tips
- A valid certificate is only half of it: make sure http redirects to https with the Redirect Checker.
- Write the https redirect and an HSTS header for Apache with the .htaccess Generator.
- A CAA record decides which authorities may issue certificates for your domain. Look it up with the DNS Checker.
- After renewing, check again: many servers keep serving the old certificate until the web server is reloaded.
Frequently asked questions
Can’t find your answer? Contact us — we reply quickly.
How do I check when an SSL certificate expires?
Enter the host name and press Check. The result shows the days left and the exact expiry date. Use “Add expiry reminder” to download a calendar entry that alerts you two weeks before that date.
What does “certificate does not match the host name” mean?
The name you connected to is not listed in the certificate. A certificate for www.example.com does not cover example.com or shop.example.com unless those names are listed too. A wildcard such as *.example.com covers one level of subdomains, but not the bare domain.
What is an intermediate certificate?
Certificate authorities do not sign site certificates with their root certificate directly; they use an intermediate one. The server must send it along with the site certificate. If it is missing, clients that do not already know it cannot build the chain to a trusted root and reject the connection.
What is the difference between SSL and TLS?
TLS is the successor of SSL. The SSL protocol versions are obsolete and no longer accepted by current browsers; today’s connections use TLS 1.2 or 1.3. The term “SSL certificate” has stuck, but the same certificate works with every TLS version.
What is sent to your server?
Only the address or domain name you enter. A browser is not allowed to make this kind of request itself, so our server makes it for you and returns the result. We do not store the address or the result, and the content of the checked pages is never passed on.
Why is there a limit on the number of checks?
Each check makes our server contact another website. To keep the tool from being used to flood or probe other sites, the number of checks per minute and per day is limited, and private or internal network addresses are refused. Wait a moment and try again.
More free SEO and website tools
Generate tags and files, check status codes, redirects, DNS and certificates — free, without an account.