SSL & TLS
Check a website’s certificate and TLS connection.
About this scan
Checks certificate trust, hostname, validity and key details on port 443. New scans also probe TLS 1.0–1.3, discover CAA records and attempt server-certificate revocation verification via CRL, within 20 seconds. Unknown checks remain explicit. Does not verify CT compliance, OCSP or enumerate every cipher.
Anyone with the result link can view the report. Reports expire after seven days. Query values and sensitive headers are redacted.
A snapshot, not a security guarantee.
From scan to solution
Get to the cause of a certificate warning
A certificate can be in date and still fail verification. CheckSSL examines the TLS connection on port 443, including trust, hostname and validity. These guides help you distinguish an approaching expiry from a name mismatch or a chain problem, so you can investigate the right part of your hosting setup.
How to check SSL certificate expiry and renewal
Read certificate dates, verify a renewal on the public endpoint and investigate why a server still presents an old certificate.
Read guide Hostname errorsHow to troubleshoot an SSL certificate name mismatch
Understand hostname coverage, wildcard limits and why an HTTPS redirect cannot fix a certificate for the wrong name.
Read guide Certificate trustSSL certificate chain errors: what to investigate
Understand leaf, intermediate and root certificates, and investigate a failed trust check without guessing the cause.
Read guideA few useful answers
Frequently asked questions
What does CheckSSL verify?
CheckSSL connects to the supplied hostname on port 443 and checks certificate trust, hostname matching, validity and key details. New scans also probe TLS 1.0–1.3, discover CAA records and attempt server-certificate revocation verification via CRL. It reports the negotiated cipher and certificate chain with public PEM downloads. CT compliance, OCSP and exhaustive cipher support are not verified. Checks that cannot finish within the scan limits remain unknown.
Why do I see an expiry warning if renewal is automatic?
CheckSSL flags a certificate that expires within 30 days. That can be normal for a short-lived certificate with working automation. Check the actual expiry and renewal process, then confirm that the public endpoint serves the renewed certificate.
How to check SSL certificate expiry and renewalShould I check www and my bare domain separately?
Yes. They are different hostnames and may serve different certificates. An HTTPS hostname needs a matching certificate even if it immediately redirects to another host. Run a check for each public name visitors use.
How to troubleshoot an SSL certificate name mismatchWhat does an untrusted diagnostic result mean?
When a verified connection fails, the tool may still obtain certificate details through a diagnostic handshake. Those details help investigation but do not prove chain trust or a hostname match. Follow the verification status rather than assuming visible certificate dates mean the connection passed.
SSL certificate chain errors: what to investigateWill CheckSSL monitor my certificate or send expiry alerts?
No. Each check is an on-demand snapshot of the connection reached at that moment. The report can be shared and remains available for seven days. Use a separate monitoring service and renewal automation for ongoing expiry management.