Skip to content
Approvalens

Free · no sign-up

SSL Certificate Checker

We connect to your site on port 443 the way a browser does and read the certificate it sends, for the name you enter and for its www or bare-domain twin. You see whether it's accepted, why not if it isn't, who issued it, when it expires and which names it covers.

Test a live site

What the SSL checker reads

  • Valid or not: the checks a browser makes. The certificate must chain to a trusted root, be inside its dates and name the host you asked for.
  • Why not: expired, not yet valid, wrong name, incomplete chain, self-signed or revoked.
  • Issuer, start date, expiry date and days left.
  • Names: the Subject Alternative Names the certificate lists, and whether the bare domain and www are both covered.
  • TLS version the server agreed to use with us.

Why a certificate gets rejected

  • Expired. Renewal stopped working: a cron job or timer that no longer runs, a DNS or HTTP challenge that now fails, or a server that renewed the file but was never reloaded.
  • Not valid for this name. The certificate covers example.com but someone opened www.example.com, or the server sends a default certificate for another site. Common on shared hosting after adding a domain.
  • Incomplete chain. The server sends its own certificate without the intermediate one. The site may look fine in one browser and fail in another tool or on another device.
  • Self-signed. Fine for testing, never for a public site.
  • Not yet valid. The start date is in the future, usually a wrong clock on the server that issued it.

Expiry and renewal

Let's Encrypt certificates are valid for 90 days today, and Let's Encrypt has announced it will cut that to 45 days by 2028. It recommends renewing at about two thirds of the lifetime when the client doesn't support ACME Renewal Information. For a 90-day certificate that's about 30 days before expiry, so a certificate with fewer days left than that usually means renewal is failing.

We flag anything under 14 days, the same threshold the full report uses. Don't wait for it: run the renewal by hand and read the error it gives.

www and the bare domain need the same certificate

People type both. A browser checks the certificate before it ever sees a redirect, so if https://www.example.com has no valid certificate the visitor gets a warning even though your server would have sent them on to example.com.

The fix is to put both names on one certificate. With Certbot that's one command, for example certbot certonly -d example.com -d www.example.com, and hosting panels usually have a checkbox for the www version.

Questions

Frequently asked questions

Does this see the same thing as my browser?

Mostly. We verify against a standard set of trusted roots and check dates and names the way browsers do. We don't check revocation lists, and a browser that fills in a missing intermediate certificate on its own can show a padlock where we report an incomplete chain.

Why does www show a different certificate?

Each name can be set up separately on the server or CDN. If www points somewhere else (an old host, a parking page, a different CDN zone), it serves whatever certificate that place has. Point both names at the same server and issue one certificate for both.

My certificate renewed but the old one still shows. Why?

The web server keeps the old certificate in memory until it reloads. Reload nginx or Apache after renewal (Certbot can do this with a deploy hook). If a CDN sits in front, it serves its own edge certificate, which is the one we read.

Which TLS version should I see?

TLSv1.2 or TLSv1.3. TLS 1.0 and 1.1 are formally deprecated (RFC 8996 says they must not be used), so if the server offers only those, update its TLS settings.

How often can I run it?

Results are kept for 5 minutes per domain. After you fix something, wait that long before checking again.

Guides

Guides that use this tool

Where this check comes up, and how to fix what it finds.

Next step

One check here, the whole site in the report

This is one of 258 checks. Scan the whole site for the full picture; the first 50 pages are free.

First 50 pages free · no sign-up · no card