How to Check an SSL Certificate (and When It Expires)
An expired or misconfigured SSL certificate puts a full-page security warning in front of every visitor. Here's how to check any site's certificate and expiry date — in your browser, online, or on the server — and how to fix the errors you're most likely to hit.
In Chrome, click the tune/padlock icon left of the address → Connection is secure → Certificate is valid to see the issuer and expiry date. Online, an SSL checker shows the whole chain, days left, TLS versions and HTTPS redirect in one go. On a server, run openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -dates.
Check an SSL certificate in Chrome, Edge or Firefox
Chrome and Edge: click the icon to the left of the address bar → Connection is secure → Certificate is valid. The Details tab shows who issued it, which names it covers and the Valid to date. Firefox: padlock → Connection secure → More information → View certificate.
This shows the certificate your browser received, but not problems other visitors may hit, like a missing intermediate certificate that your browser happens to have cached.
Check it online (most complete)
The SSL Checker connects to the server and verifies the full chain against trusted roots, the hostname match and days until expiry, tests TLS 1.0–1.3 separately, and checks that http:// redirects to https:// with HSTS. To watch many domains at once, paste them into the Certificate Expiry Checker, which sorts them by days left.
Check it on a Linux or Windows server
Linux/macOS: echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates -issuer -subject. For a certificate file: openssl x509 -in cert.pem -noout -enddate.
Windows Server: open certlm.msc (Local Computer certificates) → Personal → Certificates and check the Expiration Date column, or in IIS Manager open Server Certificates.
Fix the most common SSL errors
Expired certificate: renew it, and make sure automatic renewal (certbot, your host, Cloudflare) actually reloads the web server. Incomplete chain / “unable to verify the first certificate”: install the full chain (fullchain.pem), not just the leaf certificate. Name mismatch: the certificate must cover the exact hostname, including www. Old TLS versions: disable TLS 1.0 and 1.1 and keep 1.2 and 1.3. Mixed content warnings: find http:// resources with the Mixed Content Checker.
Why certificate expiry matters more every year
The CA/Browser Forum is shortening the maximum certificate lifetime: 200 days from March 2026, 100 days from 2027 and 47 days from 2029. Manual renewals won't keep up — automate with ACME and monitor expiry dates.
Try Free Web Tools Mentioned in This Guide
SSL Checker
Check a site's SSL/TLS certificate, chain, expiry, TLS versions, HTTPS redirect and HSTS.
Certificate Expiry Checker
Check SSL certificate expiry dates for up to 20 domains at once.
Mixed Content Checker
Find insecure http:// scripts, stylesheets, images and iframes on an HTTPS page.
Security Headers Checker
Scan any website's HTTP security headers and get an A+ to F grade with fixes.
Frequently Asked Questions
How do I know if a website's SSL certificate is valid?↓
Browsers show a warning page if it isn't. For details — issuer, expiry, chain and TLS versions — run the domain through an SSL checker.
What happens when an SSL certificate expires?↓
Browsers block the site with a “Your connection is not private” warning, APIs and apps fail to connect, and search engines may drop pages.
Is a free Let's Encrypt certificate as secure as a paid one?↓
Yes — encryption is identical. Paid certificates differ in validation type, warranty and support, not in the security of the connection.