Sign up free

SSL Certificate Checker

See who issued a site's certificate, when it expires, which names it covers and whether it's trusted.

About SSL Certificate Checker

Run this SSL certificate checker when a browser shows a security warning, before a certificate is due for renewal, or right after installing a new one on Nginx, Apache, a CDN or a hosting panel. Enter a host name, or host:port for a service on another port. We read the certificate and the chain the server actually sends, and test trust against the Mozilla root store, the list of authorities used by Firefox and many other programs. If the certificate checks out but the padlock is still missing, the Mixed Content Checker finds the http:// files to blame.

The checks cover days left, with a warning under 30 and a failure under 7, whether the certificate matches the host name (wildcards included), key type and size, the signature algorithm, a missing intermediate certificate, TLS 1.0 or 1.1 still enabled, TLS 1.3 support and a lifetime over 398 days. Details list the issuer, validation level (DV, OV or EV), covered names, serial number, SHA-256 fingerprint, OCSP address, SCT count, and the negotiated protocol and cipher, with a chain table and a protocol table. The IP address links to IP WHOIS.

How to use SSL Certificate Checker

  1. 1
    Enter the host

    Type example.com, or example.com:8443 for a service on another port.

  2. 2
    Click Check

    We connect from our server, read the certificate chain and try each TLS version.

  3. 3
    Read the verdict

    Failures come first, each with a line on how to fix it.

  4. 4
    Check the details

    Issuer, covered names, fingerprint and the chain table sit below the checks.

Why use Cubfile for this

  • Expiry countdown

    Days left, with a warning at 30 days and a failure at 7.

  • Chain and trust

    Spots a missing intermediate and checks trust against the Mozilla root store.

  • Name matching

    Compares the host with the covered names (SAN), wildcards included.

  • TLS versions

    Shows which of TLS 1.0, 1.1, 1.2 and 1.3 the server accepts.

FAQ

SSL Certificate Checker: questions and answers

Why does the SSL checker say the chain is incomplete?
The server sends only its own certificate, without the intermediate one. Some desktop browsers fill the gap, but many apps and older phones fail. Install the full chain, often a file called fullchain.pem, on your server or CDN.
When should I renew my SSL certificate?
Before the last 30 days, when this checker starts warning. Free certificates are short-lived, so make sure automatic renewal is really running.
Can I check a certificate on a port other than 443?
Yes. Enter host:port, for example mail.example.com:993 or example.com:8443.
Can it check servers on my internal network?
No. We only connect to public internet addresses, so 192.168.x.x and other private addresses can't be reached from our server.
Is the SSL certificate checker free?
Yes, with no sign-up and no daily tasks used. The check runs when you click and the result isn't stored.
Share SSL Certificate Checker with a friendIt runs in any browser, and they can try it without signing up.

Related tools

WEB Website Speed TestTime DNS, connection, first byte and download for a page, and see what slows it down.
HTTP HTTP Status Code CheckerCheck the status code of one URL or a whole list at once.
HTTP Redirect CheckerFollow every redirect hop, with status codes and timing, and catch loops.
WEB Website Technology DetectorSee the CMS, frameworks, analytics, CDN and server a website uses.
WEB Is It Down?Find out whether a site is down for everyone, and which step fails.
WEB CDN CheckerFind out whether a domain is behind a CDN, and which one.
WEB GZIP and Brotli CheckerCheck whether a page is sent compressed and how much it saves.
WEB Hacked Website CheckerLook for spam redirects, hidden links and content shown only to search engines.