Free checks for your website, domain and email
Free SSL certificate checker
Enter a website to see whether HTTPS answers and which certificate authorities your domain allows. From launch, the same check reads the certificate itself – its expiry date and its chain – from outside your network.
What this checker looks at
The certificate the site presents over HTTPS: its expiry date, the names it covers and whether its chain leads to an authority browsers trust. It also checks that the site answers over HTTPS and reads the domain’s CAA records, which say which authorities may issue certificates for it.
What a failing result means
An expired or untrusted certificate makes browsers show a full-page warning, and most visitors leave. A name the certificate does not cover gives the same warning on that address. A CAA record that leaves out your certificate authority stops your next renewal.
How to fix it
Renew the certificate with your host or certificate authority, or turn on automatic renewal. If the chain is the problem, install the intermediate certificates your authority provides. If CAA blocks renewal, add your authority to the domain’s CAA records, then run the check again.
Questions people ask
- How early should a certificate be renewed?
- Well before it expires. Automated certificates usually renew about 30 days ahead, so a certificate with under two weeks left often means renewal has stopped working.
- Does this check change anything on my site?
- No. It reads only what any visitor’s browser and public DNS can see.
Read the guide: SSL certificate expired: what it means and how to fix it
Keep it checked, free
Never let a certificate expire: Xovris watches it every 5 minutes and warns you weeks before it lapses, not the day it breaks.
Xovris opens at launch – join early access and your site is the first thing it checks.