SSL Certificate Checker (Expiry & Issuer Lookup)
Enter a domain name to check its SSL/TLS certificate's expiry date, issuer, SAN, and fingerprint. Days remaining are color-coded so you never miss a renewal and risk site downtime.
Checking a certificate's expiry and issuer
Enter a domain name and this tool shows the expiry, the issuer, the SAN list of host names covered and the fingerprint of the SSL/TLS certificate. The days remaining are colour-coded, so a lapse that would take the site down can be caught well before it happens.
**A valid certificate is not by itself grounds for confidence. The commonest pitfall is a missing intermediate certificate.** A server must send not only its own certificate but **the intermediates leading up to the root authority as well.** Where these are absent the symptom is a particularly awkward one: **the site looks fine in a browser that happens to hold the intermediate already, while validation fails in one that does not.** **The other point is the SAN, since modern browsers no longer look at the common name at all.** Unless the host name actually in use appears in the SAN, a warning is shown however valid the certificate may be.
How to use it
- Enter the domain name Give it in the form `example.com`.
- Check the days remaining **They are colour-coded, so anything nearing renewal stands out at once.**
- Look at the SAN list **Confirm that every host name you actually use appears there.**
- Check the issuer See whether it was issued by the authority you intended.
Tips for getting more out of it
- Check expiry dates well ahead of time. Renewing 2-4 weeks before expiry gives you a buffer in case the renewal process runs into trouble.
- Free certificates from Let's Encrypt and similar CAs only last 90 days, so it's worth checking here periodically that your auto-renewal is actually working.
- The browser padlock icon only tells you whether a certificate is currently valid — it never shows how many days are left, which is exactly the gap this tool fills.
- The SAN (Subject Alternative Names) field can list several hostnames beyond the main domain, such as a www subdomain. It's worth checking that no unexpected domains are included.
- The fingerprint uniquely identifies a certificate. Comparing fingerprints before and after a renewal is a reliable way to confirm the swap actually happened.
Where it comes in useful
Guarding against a missed renewal
**A lapsed certificate makes the whole site unreachable.**
Confirming after a renewal
You can establish from outside that the new certificate has really taken effect.
On adding a subdomain
**If the new host name is absent from the SAN, a warning appears on that one alone.**
Taking a lead from other sites
You can see which authority they use and what validity period they have chosen.
Certificate terms
- Expiry
- The end of the period for which a certificate may be used. **Short periods of around ninety days now predominate, on the assumption of automatic renewal.**
- SAN
- The list of host names a certificate covers. **Modern browsers look here alone and never at the common name.**
- Intermediate certificate
- The certificate linking the root authority to your own. **Unless the server sends it too, validation fails in some environments.**
- Fingerprint
- The hash of a certificate, used to tell whether two are the same.
- Issuer
- The certification authority that issued the certificate.
- Wildcard certificate
- A certificate covering one level of subdomains together, written as `*.example.com`.
Frequently asked questions
Side Note — A brief history of SSL/TLS certificates and certificate authorities
The HTTPS connections we rely on every day trace back to SSL (Secure Sockets Layer), developed by Netscape in 1994. Early SSL 2.0 had serious vulnerabilities, and after SSL 3.0 the protocol was standardized as TLS (Transport Layer Security) 1.0 in 1999. The name changed, but the core design — encrypting traffic using certificate-based public-key cryptography — has carried through to today.
Certificate authorities (CAs) verify that an applicant genuinely controls a domain before issuing a signed certificate. Obtaining a certificate used to cost money and take real effort, but that changed dramatically in 2016 when the nonprofit ISRG launched Let's Encrypt, a free CA. Its certificates are only valid for 90 days, though, which effectively requires automated renewal tooling such as certbot in any real deployment.
An expired certificate is more than a scary browser warning — it can escalate into a serious outage. There have been repeated, well-publicized incidents of major API services and even large financial institutions going down for hours because a certificate renewal was missed, which is why ongoing monitoring remains an operational necessity rather than a one-time setup task.