Daily Website Report
Free tool

SSL Checker

Check any website's SSL certificate in seconds: when it expires, which addresses it covers, whether browsers trust it, and what to fix. Free, no signup.

Why SSL certificates still expire

An SSL (TLS) certificate is what lets your site load over https:// with a padlock. Every certificate has an end date, and when it passes, visitors see "Your connection is not private" instead of your website. Most certificates renew themselves today, but renewals fail quietly when DNS or hosting changes, a firewall blocks the renewal check, or the server that ran the renewal was replaced.

Certificate lifetimes are also getting shorter: the maximum dropped to 200 days in March 2026 and falls in steps to 47 days by 2029. More renewals means more chances for one to fail unnoticed. Read what happens when a certificate expires, and how to fix it.

What this checker looks at

CheckWhy it matters
Expiry dateAfter it, every browser blocks the site with a warning.
Trusted by browsersSelf-signed certificates, missing intermediate certificates and untrusted issuers all trigger warnings.
Names coveredA certificate for www.example.com doesn't automatically cover example.com.
http to https redirectWithout it, people who type your address without https stay on the insecure version.
Protocol and keyOld TLS versions and short keys are rejected by modern browsers.

Frequently asked questions

How do I check when my SSL certificate expires?

Enter your domain above and the expiry date is shown in the results. In a browser you can also click the padlock or site-settings icon next to the address, then "Connection is secure" and "Certificate is valid".

My certificate renews automatically. Do I still need to check it?

Yes. Automatic renewal fails quietly when DNS or hosting changes, a firewall or CDN blocks the renewal check, or the renewal job stops running. Let's Encrypt stopped sending expiry reminder emails in 2025, so nobody tells you when that happens.

What does "certificate doesn't verify" mean?

Browsers couldn't confirm the certificate is genuine. The most common causes are an expired certificate, a certificate issued for a different name (for example only www), a self-signed certificate, or a server that isn't sending the intermediate certificate chain.

Do I need a certificate for both www and the bare domain?

If people can reach your site at both addresses, yes. One certificate can cover both names; most hosts let you tick both when issuing it.

Is this check safe to run on any site?

Yes. It makes one normal secure connection, the same as a browser opening the homepage, and one request to http:// to see whether it redirects. It doesn't scan ports or try anything else.