Free domain tool

SSL certificate checker

Check the live SSL certificate returned by a public website on port 443. See when it expires, who issued it, whether it matches the hostname and which TLS connection details were negotiated.

  • No account required
  • Public websites only
  • Results are not permanently stored
Ech the Tech Fox
Quick guide Enter a domain to see the live certificate, expiry date and hostname match.

SSL certificate lookup

Check a website's current certificate

Enter a domain such as example.com or a full HTTPS address. The checker connects on the standard HTTPS port, 443.

Examples: example.com, www.example.com or https://example.com/page

Public checks only. The checker connects to the resolved public IP address on port 443. Private, reserved and local network destinations are rejected.

What it checks

The main certificate and TLS details

The result shows the certificate returned during a live connection. Some websites use a CDN or security proxy, so the certificate may be presented on the site's behalf.

01

Expiry date

Shows when the certificate expires and how many days remain.

02

Hostname coverage

Checks whether the requested domain is covered by the certificate names.

03

Trust validation

Tests the certificate against the certificate authorities trusted by the server.

04

Issuer

Displays the organisation and certificate authority named as the issuer.

05

TLS connection

Shows the negotiated TLS protocol and cipher when the connection succeeds.

06

Fingerprint

Provides the SHA-256 fingerprint for the certificate returned by the server.

SSL questions

Common certificate questions

These answers cover expiry warnings, hostname checks and what this public SSL checker can and cannot confirm.

What does an SSL certificate protect?

A valid TLS certificate helps encrypt data between a browser and the website and allows the browser to check the hostname it connected to. It does not prove that every statement on a website is accurate or that the website is risk-free.

Why can a valid website show an expiry warning here?

The certificate may be within 30 days of expiry. It can still be valid, but the website operator should renew or replace it before the expiry date.

Why does the certificate name differ from the website company?

A hosting provider, CDN or security proxy may supply the certificate. The important check is whether the requested hostname is included in the certificate names.

Can this checker inspect an internal server or custom port?

No. The checker only connects to publicly resolved IP addresses on the standard HTTPS port 443. Private, reserved and local network addresses are blocked.

Are lookup results stored?

Results may be cached briefly to reduce repeated network requests and then expire automatically. The plugin does not create a permanent history of checked domains.