Skip to main content

Free · no signup

SSL Certificate Checker

Check any certificate’s expiry, chain, protocol, cipher and fingerprint — with an A+–F grade.

Why your SSL/TLS certificate needs watching

An SSL certificate proves your site is who it says it is and encrypts everything between it and your visitors. But certificates expire — and an expired one turns your site into a full-screen browser warning that scares customers away. Beyond expiry, the details matter:

Expiry countdown

The #1 cause of preventable outages. Renew at least two weeks out.

Chain validity

A missing intermediate makes some clients reject an otherwise valid cert.

Protocol & cipher

Modern TLS 1.2/1.3 with strong ciphers; anything older is a liability.

Fingerprint

A stable SHA-256 fingerprint lets you spot an unexpected certificate swap.

Frequently asked questions

It opens a live TLS connection to your domain and reports the certificate’s expiry date and days remaining, the issuer, whether the chain validates, the negotiated protocol (e.g. TLS 1.3) and cipher, the key size and the SHA-256 fingerprint — plus an overall A+–F grade.

Renew well before expiry — at least 14–30 days. An expired certificate makes browsers block your site. CompleteStatus can watch the expiry countdown continuously and alert you weeks ahead so you never get caught out.

Yes. Enter the domain and pick a standard TLS port (443 for HTTPS, 465 for SMTPS (implicit TLS), 993/995 for IMAPS/POP3S, 8443 for alt-HTTPS). The tool connects to that port and grades whatever certificate it serves. Port 587 (mail submission) is not offered: it starts in plaintext and upgrades with STARTTLS, which this tool does not speak.