SSL Certificate Checker
Enter a domain and the server will connect to port 443, fetch the TLS certificate, and show whether it is trusted, valid for the host, and within its validity period.
SSL Certificate Checker helps inspect HTTPS certificates for public domains. It shows whether the certificate is currently valid, whether the hostname matches the certificate names, and whether PHP can verify the trusted certificate chain.
The result includes issuer, subject, Common Name, Subject Alternative Names, validity dates, days until expiration, serial number, SHA-256 fingerprint, TLS protocol, cipher, and resolved server IPs.
The checker connects server-side to port 443 using SNI and blocks private or reserved addresses. It is useful for diagnosing expired certificates, wrong hostnames, missing intermediate certificates, and CDN or hosting TLS setup problems.
How to use it
- Enter the domain you want to connect to over HTTPS. Port 443 is used by default.
- The server opens a TLS connection with SNI and fetches the certificate chain, just like a browser does.
- The report shows whether the certificate is trusted, whether the host name matches the Common Name or SAN, the validity window and days left, the issuer, serial number and SHA-256 fingerprint.
When it helps
- Before expiry: see how many days are left and whether certbot actually renewed.
- “Your connection is not private”: find the cause quickly — expired, wrong domain in SAN, or self-signed.
- After moving hosts: confirm the new certificate is served, not the old one from the previous server.
- Subdomain audit: check whether a wildcard certificate covers a given host.
Frequently asked questions
The certificate is valid but the browser still complains. Why?
Most often the server does not send the intermediate certificate and the chain cannot be built. Make sure the configuration points at fullchain, not just the leaf certificate.
What is SAN?
Subject Alternative Names — the list of every host name the certificate covers. Modern browsers check it rather than the Common Name.
Can I check a non-standard port?
The tool connects to 443 only. For other ports use openssl s_client on your own machine.