SSL Checker
Inspect the live TLS certificate served by a public domain, including public trust, hostname coverage, expiry, issuer, SANs, fingerprint, negotiated TLS version, cipher, and ALPN.
- Live TLS Handshake
- Trust & Hostname
- Expiry Countdown
- SANs & Fingerprint
- TLS & Cipher
Enter a public domain, subdomain, international domain, or HTTP/HTTPS URL.
Inspect a live SSL/TLS certificate
Public trust, hostname coverage, expiry, issuer, SANs, fingerprint, protocol, cipher, and ALPN will appear here.
example.com
Hostname, dates, and public trust verification passed.
- Subject common name
- -
- Subject organization
- -
- Issuer
- -
- Issuer organization
- -
- Certificate version
- -
- Serial number
- -
- Validity duration
- -
- SHA-256 fingerprint
- -
What is the SSL Checker?
The SSL Checker opens a live TLS connection to a public domain and inspects the certificate that server presents at that moment. It independently records the certificate details and performs a browser-style verified handshake using the server's public trust store.
The report separates public trust, hostname coverage, validity dates, and the negotiated connection. It is a focused certificate and handshake check—not a full cipher inventory, vulnerability scan, Certificate Transparency history search, revocation monitor, or permanent uptime monitor.
How to check an SSL/TLS certificate
- Enter a public domain or an HTTP/HTTPS website URL. A port included in the URL is recognized when it is supported.
- Choose the TLS port. Port 443 is correct for almost every HTTPS website; common alternate HTTPS ports are also available.
- Select Check SSL. The server resolves the domain safely and performs live unverified and verified TLS handshakes to the same public address.
- Review the trust, hostname, validity and TLS checks, then open Certificate or Connection & SANs for technical details.
- Copy the plain-language report or export the exact result as JSON for troubleshooting and renewal records.
A clearer SSL certificate report
- Shows invalid, expired, not-yet-valid, hostname-mismatch, untrusted, and renewal-warning states distinctly.
- Uses a verified TLS client context for public trust and hostname validation while still retrieving details from invalid certificates.
- Lists certificate subject, issuer, validity window, serial number, SAN coverage, and SHA-256 fingerprint.
- Reports the exact TLS version, selected cipher, encryption bits, ALPN protocol, server address, and port used by this connection.
- Blocks IP literals, private or reserved DNS targets, and arbitrary ports to prevent internal-network and port-scanning misuse.
SSL Checker FAQ
Does a valid certificate mean the whole website is secure?
No. A valid TLS certificate authenticates the hostname and protects this connection when verification passes. It does not audit application code, malware, security headers, account safety, content, or every supported protocol and cipher.
Why can my browser show a different certificate?
CDNs, regional load balancers, DNS changes, split-horizon DNS, client trust stores, and certificate rotation can change the server or trust result. This report records one connection from the DnA server at the displayed time.
What is hostname coverage?
The requested domain must match a DNS name in the certificate's Subject Alternative Name extension. A wildcard covers one label only, so *.example.com covers shop.example.com but not example.com or deep.shop.example.com.
How early should I renew a certificate?
Automated renewal should normally complete well before expiration. This tool changes to a warning state at 30 days and an urgent state at 14 days so failed automation has time to be investigated.
Does the checker test every TLS version and cipher?
No. It reports the protocol and cipher negotiated by this modern TLS client. A full compatibility or vulnerability scan requires many controlled handshakes and is outside this tool's stated scope.
Help us improve this tool
Please share what we should improve, add, or fix. You can write in the language you are comfortable with. We only save your suggestion and IP address to prevent misuse.