Skip to content

TLS certificate checker

Catch expiring or misconfigured certificates before browsers start warning your visitors.

Anonymous checks are limited to 10 per minute and 60 per hour per address. Results are cached for 60 seconds and not published anywhere.

How it measures

  • A validated TLS handshake with SNI set to the hostname decides whether the certificate is trusted.
  • If validation fails, a second diagnostic handshake captures the presented certificate so you can see why, without ever marking it as valid.
  • Days remaining are computed from the certificate's notAfter value against the current time (UTC).

Limits

  • Only implicit TLS ports are supported; STARTTLS negotiation is not performed.
  • Trust is evaluated against the public root store of the checking host; private CAs show as untrusted.
  • One check from one location; some servers present different certificates per region or client.

Troubleshooting

Hostname mismatch
The certificate's names do not include the hostname you connected to. Add the name as a SAN or point the hostname at the correct server.
Untrusted chain
An intermediate certificate is probably missing. Serve the full chain, not just the leaf.
Expired
Renew the certificate. Automate renewal and monitor expiry so this does not recur.

Related tools