SSL Checker
Verify a website's SSL/TLS certificate: validity, issuer, certificate chain, TLS version and domain match.
About this tool
SSL Checker connects to the server just like a browser and inspects its certificate. It shows which domains it covers, who issued it, when it expires, the key type and size, the TLS version and the cipher used. It walks the whole chain up to the root authority and warns about a missing intermediate certificate, upcoming expiry, a domain mismatch or an obsolete protocol.
Glossary
- SSL/TLS
- The protocol that encrypts the connection between a browser and a server (HTTPS). SSL is the old name, today TLS 1.2 and 1.3 are used.
- Certificate
- An electronic proof that a server belongs to a domain. It contains a public key, a validity period and the signature of a certificate authority.
- Certificate authority
- A trusted organization that issues certificates (e.g. Let's Encrypt, DigiCert). Browsers keep a list of authorities they trust.
- Certificate chain
- The website certificate is signed by an intermediate certificate, which is signed by the authority's root certificate. The server must send the intermediates too, otherwise some devices reject the connection.
- SAN (alternative names)
- The list of domains the certificate is valid for, e.g. example.com and www.example.com. An asterisk (*.example.com) covers one level of subdomains.
- Self-signed certificate
- A certificate signed by itself, not by an authority. It encrypts the connection, but the browser cannot verify who owns it and shows a warning.
How to use
- 1Enter a domain, a URL or a domain with a port.
- 2Click Check certificate.
- 3Look at the overall status and the expiry date.
- 4Make sure the chain ends with a trusted root authority.
- 5Fix the reported problems and run the check again.
Specifications and limits
Port 443 is checked, or another allowed TLS port given after a colon (e.g. 993 for IMAPS). Trust is verified against the Node.js root certificate store (Mozilla). The TLS version shown is the one the server negotiated with a modern client. Connections to internal and private addresses are blocked.