Check the SSL certificate of any website — expiry date, issuer, validity status and more.
Enter any domain name without https:// — e.g. github.com
When a browser opens an HTTPS site it quietly checks four things: the certificate was issued by a trusted authority, it covers the exact domain name being visited, it has not expired, and it links back to a trusted root through a complete chain of intermediate certificates. If any of these fail, visitors get a full-page security warning and most of them leave. This checker runs the same tests from outside your network so you can find problems before your visitors do.
Check again once the new certificate is installed. Web servers often keep serving the old one until they are reloaded, and CDNs or load balancers may hold their own copy, so the certificate on your server is not always the one visitors actually receive.
The CSR generator creates the signing request, the CSR decoder confirms its details before you submit it, and the certificate key matcher confirms the issued certificate pairs with your private key before you deploy it.