Free agency tools / SSL Certificate Checker
Is this SSL certificate healthy?
Check any domain's SSL/TLS certificate - who issued it, when it expires and which hostnames it covers - so an expired or mismatched certificate never takes a client's site offline on your watch.
Results for
How it works
- 1Enter a domain - we look up its most recent publicly-logged certificate.
- 2You get the issuer, the valid-from and valid-until dates and a live expiry countdown.
- 3The certificate's covered hostnames (SANs) are listed so you can confirm it matches the site.
Frequently asked
Where does this data come from?
We open a real TLS connection to the site and read the exact certificate it serves - the same one a browser sees - so the issuer is always the live CA. If the live handshake can't complete, we fall back to public Certificate Transparency logs and say so.
Why did another tool show a different issuer?
Tools that only read Certificate Transparency logs list every certificate ever issued for a domain, not the one actually served - so a site on Let's Encrypt can wrongly show an AWS or Google cert issued for a subdomain. Reading the live handshake avoids that.
How much expiry warning do I need?
Renew at least 2-4 weeks before expiry. Most automated systems (like Let's Encrypt) renew at 30 days left; if you're inside that window and it hasn't renewed, investigate now.
What does 'covers these names' mean?
A certificate is only valid for the exact hostnames (or wildcards) listed on it. If a site is served on a name the certificate doesn't cover, browsers show a security warning.