SSL Certificate Checker

Check the certificate a website serves on port 443: when it expires, the names it covers, the full chain and whether browsers will trust it.

  • Free
  • No Sign-Up
  • Live Lookup

Examples:

How to Use

How to use the SSL Certificate Checker

  1. 01

    Enter a host name

    Such as example.com or shop.example.com. A full URL works; the path is ignored.

  2. 02

    Check

    Frabs connects on port 443, as a browser would, and reads the certificate the server sends.

  3. 03

    Read the verdict

    Trusted, matching the name and not close to expiry is what you want to see.

Security & Abuse

About the SSL Certificate Checker

What makes a certificate trusted

A browser trusts a certificate when it chains up to a root it already knows, has not expired and covers the name typed in the address bar. Servers must send the intermediate certificates as well as their own; a missing intermediate is the most common reason a site works in one browser and fails in another, or in curl.

Names are listed in the Subject Alternative Name field. A wildcard like *.example.com covers shop.example.com but not example.com itself, and not a.b.example.com.

Expiry and renewal

Public certificates now last at most 398 days, and Let's Encrypt and Google's issue for 90 days, with lifetimes shrinking further over the next few years. Automatic renewal is the only safe approach: if this tool shows fewer than 14 days left on an automated certificate, renewal is probably failing.

What it can't tell you

  • Port 443 only. Mail (25, 465, 587) and other ports are not checked.
  • Revocation (OCSP and CRLs) is not checked.
  • A site behind a CDN shows the CDN's certificate, not the one on your origin server.

Frequently asked questions

How do I check when an SSL certificate expires?
Enter the site's host name above. The result shows the expiry date and the days left. In a terminal you can also run: openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -enddate
What does 'unable to verify the first certificate' mean?
The server sent its own certificate without the intermediate. Configure the full chain file (fullchain.pem with Let's Encrypt) instead of the certificate alone.
Is TLS 1.2 still OK?
Yes, TLS 1.2 with modern ciphers is still considered secure. TLS 1.0 and 1.1 are deprecated and should be switched off.
Why does it show a different certificate from my server?
If the site is behind Cloudflare or another CDN, visitors connect to the CDN, so its certificate is the one shown.

Stop abuse leaving your servers

Frabs watches every VM's outbound traffic and stops spam, scans and floods before the abuse report arrives.