Expired or near-expiry certificates
Expiry windows matter because browsers and automated clients will reject invalid certificates as soon as the validity period ends.
Use this free website SSL checker and domain SSL checker tool for public HTTPS hosts. Review certificate validity, expiry, issuer, chain health, TLS details, and security hints in one place.
Enter a hostname or paste a website URL, for example www.google.com or https://example.com. The checker normalizes the value before testing port 443.
Review the current certificate state, issuer, and expiry details.
Leaf certificate fields, SANs, chain information, and the OpenSSL command output are shown below.
A quick view of overall certificate health and the strongest immediate follow-up items.
Use the free bulk SSL checker to test up to 500 domains in one run. Add hostnames separated by spaces or new lines; the tool validates each FQDN against its certificate, follows the final URL status, and shows expiry dates in a table.
Use up to 500 hostnames. Protocols and paths are cleaned automatically.
| S.No | Website Name (FQDN) | HTTP Status | SSL Domain Verification | SSL Certificate Expiry | Details |
|---|
These commands help you verify certificates locally from a terminal or server shell.
openssl s_client -connect example.com:443 -servername example.com -showcerts
openssl x509 -in certificate.crt -text -noout
openssl x509 -in certificate.crt -noout -dates
openssl verify -CAfile ca-bundle.crt certificate.crt
Expiry windows matter because browsers and automated clients will reject invalid certificates as soon as the validity period ends.
The certificate must match the host your users visit. SAN mismatches are a common cause of browser security warnings.
Missing intermediates can make a certificate appear valid on one machine and fail on another that does not already have the chain cached. Use the Certificate Chain Composer to build fullchain.pem.
Use the Certificate Checker when you need to inspect a PEM certificate or full chain without running a live domain scan.
Start with the hostname match, certificate validity dates, issuer, and chain status. A certificate can be cryptographically valid but still fail for users if the SAN list does not include the exact hostname, if an intermediate certificate is missing, or if the web server redirects visitors to a different name that is not covered by the certificate.
For production sites, check the certificate before renewal windows close and again after deployment. Bulk checks are useful for teams that manage many domains, load balancers, CDN hostnames, or customer-facing portals. If one hostname fails while another succeeds, compare the certificate chain, SNI behavior, redirect target, and DNS record behind each name.
Confirm the active certificate expiry date, SAN coverage, issuer, and current chain so you know exactly what needs to be replaced.
Run a fresh check against the public hostname, not only the server file path, because users experience the certificate served by the live endpoint.
Use the Certificate Checker for pasted PEM data and the Certificate Chain Composer when a server needs a complete fullchain file. If users still report HTTPS or site loading errors, follow the Website Not Opening Troubleshooting Guide.
The checker connects to the public hostname on TCP port 443 and requests the certificate that the web server presents during the TLS handshake. Server Name Indication is included so hosting platforms, reverse proxies, load balancers, and CDNs can return the certificate configured for that exact domain. The result therefore reflects the certificate a normal HTTPS visitor is likely to receive, rather than a certificate file stored privately on a server.
Compare the current time with the certificate's valid-from and valid-until dates. A near-expiry result means renewal and public deployment should be scheduled before browsers begin rejecting the connection.
The requested hostname must match a Subject Alternative Name. A certificate for the root domain does not automatically cover every subdomain unless an appropriate wildcard or explicit SAN is present.
Review the issuer, intermediate chain, TLS version, cipher suite, and HSTS result together. These fields help distinguish a certificate problem from a wider HTTPS configuration problem.
The bulk checker is designed for domain portfolios, customer portals, branch appliances, APIs, load balancers, CDN hostnames, and migration inventories. Paste up to 500 hostnames separated by spaces or new lines. Protocols and paths are removed, duplicate entries are normalized, and each fully qualified domain name is checked independently so one unavailable website does not hide the remaining results.
Run the list before a renewal, after certificates are deployed, and after DNS, CDN, proxy, or load-balancer changes. Keep critical production names in routine monitoring even when automated renewal is enabled: automation can obtain a certificate successfully while a listener, virtual host, or secondary endpoint continues serving the old one.
An HTTPS address is a useful first sign that a site is configured for encrypted connections, but it does not tell you whether the certificate is current, covers the requested hostname, or includes the chain needed by connecting clients. This checker reads the certificate presented by the public endpoint so you can review those details without relying only on a browser warning.
The hostname and SAN fields show which names the certificate covers. The issuer identifies the certificate authority that signed it, while the validity dates show when the certificate can be used.
A chain connects the leaf certificate served by the website to trusted certificate authorities through any required intermediate certificates. An incomplete chain can fail on some clients even when the leaf certificate dates look correct.
Fingerprints provide compact identifiers for comparing certificates. Public-key and PEM details are useful when troubleshooting an installation or comparing the live certificate with a certificate file held by an administrator.
An SSL status check shows whether a public website presents a usable SSL/TLS certificate for the requested domain. A healthy SSL certificate status normally means the certificate is within its validity period, includes the exact hostname, and provides a chain that clients can link to a trusted certificate authority. Use the form above to check a domain SSL status against the certificate served on port 443.
The certificate is current and matches the website hostname. Still review the chain, TLS version, redirect destination, and remaining days so a valid certificate does not hide a deployment or renewal risk.
The current time falls outside the certificate validity window. Confirm the server clock, renew or replace an expired certificate, and make sure the live listener is serving the newly installed certificate.
A hostname error means the requested domain is not covered by the certificate SANs. A chain error commonly indicates a missing intermediate certificate or another trust-path problem.
This status means a TLS connection could not be completed. Check DNS, port 443, firewall rules, the HTTPS virtual host, SNI configuration, and whether the server is reachable before testing again.
To check SSL status in Linux or Ubuntu, you can also run openssl s_client -connect example.com:443 -servername example.com. Messages such as pending or initializing certificate in a hosting or DNS provider dashboard often describe that provider's issuance workflow, not the certificate currently served by the website. Test the public hostname to distinguish a pending deployment from the live SSL status.
This SSL online checker tests the certificate presented by a live HTTPS website. To verify SSL online, enter a public domain above and review its validity, expiry, hostname coverage, issuer, chain, TLS version, and cipher. The result is an SSL online test of the active endpoint, so it can reveal when a server still presents an old or incorrect certificate after deployment.
Use the single-domain form for a quick online SSL check or the bulk SSL checker when you need to check SSL online across many websites. Bulk results make it easier to find expired certificates, hostname mismatches, connection failures, and domains approaching renewal.
This page checks deployed certificates; it does not sell, create, or generate SSL certificates. To decode an SSL certificate online from pasted PEM data instead of testing a live website, use the Certificate Checker. Certificate issuance—including free Let's Encrypt SSL—must be completed through a certificate authority, hosting provider, or ACME client before the live endpoint can be verified here.
An SSL expiry check reads the validity dates from the certificate currently served by a website. Enter a hostname above to check or find the expiry date of its SSL certificate, see the remaining number of days, and confirm that the live certificate matches the intended domain. The bulk SSL expiry checker can review up to 500 hostnames when you manage multiple websites, APIs, CDNs, or load balancers.
Run the online test and review the certificate's valid-from and valid-until values. A result close to expiry should be scheduled for renewal, deployment, and another public check before the remaining time reaches zero.
A one-time check shows the current state; monitoring repeats the check and alerts before expiry. Track every production hostname, including redirect targets, APIs, CDN endpoints, secondary servers, and failover systems.
Obtaining a new certificate does not prove it is live. Repeat the expiry check after installation to confirm the public endpoint serves the replacement certificate and complete chain.
Use OpenSSL with Server Name Indication so the server returns the certificate for the correct hostname:
openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates
Replace example.com with the website hostname. The notAfter value is the SSL expiry date, while notBefore shows when the certificate became valid.
On Windows, enter the hostname in this online checker to read the live certificate and its remaining lifetime. You can also open the website in a browser, view the connection or certificate information, and inspect the validity dates. If OpenSSL is installed on Windows, run the same s_client and x509 -noout -dates command shown above from your terminal.
This independent SSL checker tool provides a quick website certificate test without requiring an account. Other services may report different or additional data, so administrators sometimes compare results with a Qualys SSL checker, DigiCert SSL checker, Sectigo SSL checker, SSL Shopper SSL checker, or GoDaddy SSL checker.
Certificate authority tools such as a Comodo SSL checker, GeoTrust SSL checker, or legacy Symantec SSL checker and VeriSign SSL checker may be useful when investigating a certificate issued under those brands. Product names belong to their respective owners; Networking Essentials is not affiliated with or endorsed by these providers. If you searched for “qualsys SSL checker,” the commonly used spelling is “Qualys SSL checker.”
It examines the certificate served by a public HTTPS hostname, including dates, hostname coverage, issuer, chain information, and available TLS connection details.
It checks multiple hostnames in one run and reports certificate expiry, domain verification, final HTTPS URL, response status, and certificate details for each website.
The requested hostname may be missing from the SAN list, an intermediate may be absent, or the server may present a different certificate than the one intended.
Renew early enough to deploy and test the replacement across every public endpoint before expiry. Include secondary servers, failover systems, CDNs, and load balancers in that check.
Typical renewal involves creating or reusing a certificate signing request, obtaining the replacement from a certificate authority, installing the certificate and private key through the hosting platform, and checking every public endpoint after deployment.
An SSL checker is an online tool that connects to a website and reports whether its SSL/TLS certificate is valid, current, trusted, and issued for the requested domain.
A missing padlock can be caused by mixed HTTP content, an HTTPS redirect problem, a browser-cached error, or another page-level issue. A valid certificate is only one part of a secure HTTPS page.
SSL status summarizes whether a website presents a usable SSL/TLS certificate for its domain. A healthy status generally means the certificate is current, matches the hostname, and can be linked through its certificate chain to a trusted authority.
Enter the public domain name in the SSL status checker and run the test. Review the validity dates, hostname match, issuer, and certificate chain, then investigate any connection or trust error reported for the live HTTPS endpoint.
No SSL detected usually means the checker could not complete a TLS connection on port 443. Possible causes include no HTTPS listener, DNS or firewall problems, a connection timeout, or an incorrect TLS configuration.
Enter the public hostname in the online SSL checker and run the test. Verify that the certificate is current, covers the requested hostname, has a complete chain, and is served from the HTTPS endpoint users actually visit.
Enter the website hostname in the SSL expiry checker and run the test. The certificate summary shows its valid-from date, expiry date, and remaining lifetime. Check the public hostname so the result reflects the certificate users actually receive.
Use openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates. Replace example.com with the required hostname and read the notAfter value.
Enter the hostname in this online checker from Windows, or open the website certificate through the browser's connection information and inspect its validity dates. If OpenSSL is installed, you can run the same certificate-date command from a Windows terminal.