Free tools

SSL certificate check.

See a domain's current TLS certificate, its issuer, names and expiry, from Certificate Transparency logs, and whether it is HSTS preloaded.

What it checks

Checks

  • The newest valid certificate logged in Certificate Transparency for the name: its issuer, validity dates and names (SANs).

  • How many days it has left.

  • Whether the domain is on the HSTS preload list.

Doesn’t check

  • The certificate your server presents right now. The tool reads the public logs and never connects to your server; the two almost always match.

  • TLS versions, cipher suites, or problems with the certificate chain.

  • Certificates for other names under the domain.

Questions

Why read logs instead of connecting to the server?

Browsers only trust certificates that have been logged in Certificate Transparency, so the logs show the same certificate without touching your server.

My certificate renewed, but the old one shows.

A new certificate reaches the logs as it is issued, but the log services can take a few minutes to index it. Try again shortly.

What is the HSTS preload list?

A list built into browsers of domains that are only ever loaded over HTTPS, even on a first visit. Joining is optional and slow to undo.

Where does the data come from?

Cert Spotter's API by SSLMate, with crt.sh as a fallback, and the preload status from hstspreload.org.

Is what I enter stored?

No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.

Check a whole repository,
free.