How to use
- Enter a domain name or paste a URL, then click Check SSL.
- Click Copy summary to copy the verdict and key certificate details.
- Click Download JSON to save the full result.
Examples
Check a public website
example.com
Host: example.com Verdict: Valid Issuer: Cloudflare TLS Issuing ECC CA 3, SSL Corporation Valid: 2026-09-26 – 2026-12-25 (81 days left) SANs: example.com, *.example.com Chain: trusted Checked from our server at 2026-10-05 13:27:41 UTC
Why a wildcard certificate doesn't cover this host
wrong.host.badssl.com
Host: wrong.host.badssl.com Verdict: Problems found Issuer: YR1, Let's Encrypt Valid: 2026-09-29 – 2026-12-28 (84 days left) SANs: *.badssl.com, badssl.com Chain: trusted Checked from our server at 2026-10-05 13:27:48 UTC
FAQ
How do I check when an SSL certificate expires?
Look at Valid to and Days remaining in the certificate details. The checker warns when the certificate expires within 30 days and flags expired or not-yet-valid certificates as problems.
How do I fix a missing intermediate certificate?
Configure your server to send the full certificate chain provided by your CA, often in a file called fullchain.pem. This checker does not fetch missing intermediates, so it reports an incomplete chain when your server leaves one out.
Which root certificates does this SSL checker trust?
It uses the Mozilla CA bundle packaged by certifi, not the server's system trust store. The trust store version appears below each result.
Does a valid SSL certificate mean a website is safe?
No. A valid result means the certificate has a trusted chain, matches the hostname and is within its validity dates; it does not establish that the website is safe. Revocation and Certificate Transparency are not checked.
Can I check SSL on a port other than 443?
Only port 443 is supported. You must enter a domain name, not an IP address; mail services on ports such as 465 or 993 cannot be checked.