SSL Checker

Verify a website's SSL/TLS certificate: validity, issuer, certificate chain, TLS version and domain match.

About this tool

SSL Checker connects to the server just like a browser and inspects its certificate. It shows which domains it covers, who issued it, when it expires, the key type and size, the TLS version and the cipher used. It walks the whole chain up to the root authority and warns about a missing intermediate certificate, upcoming expiry, a domain mismatch or an obsolete protocol.

Glossary

SSL/TLS
The protocol that encrypts the connection between a browser and a server (HTTPS). SSL is the old name, today TLS 1.2 and 1.3 are used.
Certificate
An electronic proof that a server belongs to a domain. It contains a public key, a validity period and the signature of a certificate authority.
Certificate authority
A trusted organization that issues certificates (e.g. Let's Encrypt, DigiCert). Browsers keep a list of authorities they trust.
Certificate chain
The website certificate is signed by an intermediate certificate, which is signed by the authority's root certificate. The server must send the intermediates too, otherwise some devices reject the connection.
SAN (alternative names)
The list of domains the certificate is valid for, e.g. example.com and www.example.com. An asterisk (*.example.com) covers one level of subdomains.
Self-signed certificate
A certificate signed by itself, not by an authority. It encrypts the connection, but the browser cannot verify who owns it and shows a warning.

How to use

  1. 1Enter a domain, a URL or a domain with a port.
  2. 2Click Check certificate.
  3. 3Look at the overall status and the expiry date.
  4. 4Make sure the chain ends with a trusted root authority.
  5. 5Fix the reported problems and run the check again.

Specifications and limits

Port 443 is checked, or another allowed TLS port given after a colon (e.g. 993 for IMAPS). Trust is verified against the Node.js root certificate store (Mozilla). The TLS version shown is the one the server negotiated with a modern client. Connections to internal and private addresses are blocked.