Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

SSL Certificate Checker

Test a website's HTTPS setup in seconds. The checker connects to the server, verifies the certificate chain against trusted roots, checks the hostname and expiry date, tests which TLS versions are enabled, and confirms that plain HTTP redirects to HTTPS with HSTS.

Enter a domain (optionally with a port). Our server performs a TLS handshake, reports whether the certificate is trusted and matches the hostname, days until expiry, issuer, key type and the full chain including intermediates, and tests TLS 1.3, 1.2, 1.1 and 1.0 separately. It also checks the http:// redirect and the HSTS header.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for SSL Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use SSL Checker

  1. 1Enter the domain, e.g. example.com.
  2. 2Read the overall result and checks.
  3. 3Review TLS versions and the certificate chain.
  4. 4Fix issues such as missing intermediates or old TLS versions.

What a healthy HTTPS setup looks like

A certificate from a trusted CA covering the exact hostname, the intermediate certificates sent by the server (a missing intermediate is the most common chain error), TLS 1.2 and 1.3 only, a redirect from http:// to https://, and an HSTS header so browsers never try HTTP again.

TLS 1.0 and 1.1 were formally deprecated in 2021 (RFC 8996) and should be disabled.

Certificate lifetimes are shrinking

The CA/Browser Forum is reducing maximum certificate validity to 200 days from March 2026, 100 days in 2027 and 47 days in 2029, so automatic renewal with ACME (Let's Encrypt, ZeroSSL, or your host) is essential. Monitor many domains with the Certificate Expiry Checker.

Frequently Asked Questions

What does “unable to verify the first certificate” mean?

The server isn't sending its intermediate certificate. Install the full chain (often called fullchain.pem) on your server.

Why is TLS 1.0 shown as “not tested”?

Our server's TLS library may refuse to offer very old protocols, so we can't always test them. If the site accepts them, a dedicated scanner like SSL Labs will show it.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Guides & Tutorials

Related Tools