Search 93+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
Security Tool

SSL Certificate Checker

Check the SSL certificate of any website — expiry date, issuer, validity status and more.

🔒 Check SSL Certificate

Enter any domain name without https:// — e.g. github.com

🔒
What this checks
SSL certificate validity, expiry date, issuer organisation, subject CN, SAN domains and signature algorithm.
⏰
Expiry alerts
See exactly how many days until your certificate expires. Get alerted at 30 days remaining — most providers auto-renew at 30 days.
🛡️
Why it matters
An expired SSL certificate breaks HTTPS for all visitors, triggers browser security warnings, and can hurt your search rankings.

Frequently Asked Questions

What does the SSL checker test?
It checks certificate expiry date, issuer, chain validity, encryption strength, hostname match and whether the certificate is trusted.
How far in advance should I renew my SSL?
Renew at least 30 days before expiry. Let's Encrypt certificates expire every 90 days and auto-renew when configured correctly.
What does "chain" mean in SSL?
The certificate chain links your certificate to a trusted root CA through intermediate certificates. A broken chain causes browser warnings.
How often should I check my SSL certificate?
Check monthly, or set up monitoring that alerts you 30 days before expiry. Most providers (Let's Encrypt, DigiCert, Sectigo) auto-renew but failures do happen — always verify manually.
What does "Certificate does not match domain" mean?
The SSL certificate was issued for a different domain than the one you're visiting. This triggers browser security warnings. Ensure your certificate covers the exact domain including www and non-www variants.
What is a SAN certificate?
Subject Alternative Name (SAN) certificates cover multiple domains with one certificate. For example, one certificate can cover example.com, www.example.com, and api.example.com.
🛡️
SSL checks your site security — VPN secures your connection. Browse securely with a VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

What an SSL certificate check covers

When a browser opens an HTTPS site it quietly checks four things: the certificate was issued by a trusted authority, it covers the exact domain name being visited, it has not expired, and it links back to a trusted root through a complete chain of intermediate certificates. If any of these fail, visitors get a full-page security warning and most of them leave. This checker runs the same tests from outside your network so you can find problems before your visitors do.

The problems it catches most often

  • Certificates about to expire. Let's Encrypt certificates last 90 days and renew automatically, until something breaks the renewal: a changed DNS record, a new firewall rule, a full disk. Nothing warns you until the site goes down, so check expiry after any server change.
  • An incomplete chain. A server that sends only its own certificate, without the intermediate, can still work in desktop Chrome, which fetches the missing piece itself, but fail on Android, older devices, curl and many payment or API clients. Install the full-chain file your certificate authority provides.
  • Name mismatches. A certificate for example.com does not cover www.example.com, or a subdomain, unless those names are listed in it. Check every hostname your visitors use.
  • Outdated protocols. TLS 1.0 and 1.1 are retired by every major browser. Servers should offer TLS 1.2 and 1.3 only.

After renewing or replacing a certificate

Check again once the new certificate is installed. Web servers often keep serving the old one until they are reloaded, and CDNs or load balancers may hold their own copy, so the certificate on your server is not always the one visitors actually receive.

Replacing a certificate

The CSR generator creates the signing request, the CSR decoder confirms its details before you submit it, and the certificate key matcher confirms the issued certificate pairs with your private key before you deploy it.

Related Tools

📜
CSR Generator
Generate a CSR online
🔍
CSR Decoder
Decode a certificate signing request
🔄
SSL Converter
Convert SSL certificate formats
🗝️
Certificate Key Match
Check SSL cert matches private key
🔏
Hash Generator
Generate MD5, SHA-256 hashes
📋
JSON Formatter
Format and validate JSON
Done!