Check your SSL certificate
Type your address. You will see when the certificate expires, who issued it and whether your visitors' browsers trust it.
What the check looks at
- Expiry
- How many days are left. The day it runs out, browsers show a warning instead of your site.
- Issuer
- Which certificate authority issued it, for example Let’s Encrypt or Google Trust Services.
- Address match
- Whether the certificate names the exact address people type, with and without www.
- Certificate chain
- Whether the server also sends the intermediate certificate. Without it some phones and apps refuse the connection, even when your laptop does not.
- TLS versions
- Which versions of the encryption protocol the server accepts. TLS 1.0 and 1.1 are retired.
- Redirect to https
- Whether someone who types http:// ends up on the encrypted https:// version.
Questions
How do I check when my SSL certificate expires?
Type your address above and look at the "Valid until" row. In a browser you can also click the icon next to the address and open the certificate details. The date that matters is the last day of validity.
What happens when an SSL certificate expires?
Browsers stop showing your site and show a full-page warning instead. Many visitors leave at that point. Contact forms, shops and logins stop working for everyone who does not click past the warning, and some mail systems refuse to connect.
The certificate is valid, so why does the browser still warn?
The three usual reasons: the certificate does not cover the exact address (often the version with or without www), the server does not send the intermediate certificate, or the page loads images or scripts over http. This check shows the first two.
Is a free Let’s Encrypt certificate as good as a paid one?
For encryption, yes: the connection is protected in exactly the same way. Paid certificates can also confirm the company behind the site, but browsers no longer show that in the address bar. For most small businesses a free certificate with automatic renewal is the sensible choice.
Why do certificates keep getting shorter?
Browser makers and certificate authorities agreed to shorten them step by step. A certificate issued from 15 March 2026 can be valid for at most 200 days, from 15 March 2027 for at most 100 days, and from 15 March 2029 for at most 47 days. Manual renewal stops being practical, so automatic renewal is the thing to ask your hosting company about.
What are TLS 1.0 and 1.1, and why switch them off?
They are old versions of the protocol that encrypts the connection to your site. They were formally retired in 2021, current browsers no longer use them, and the card payment standard PCI DSS does not allow them. Switching them off locks out nobody on an up-to-date browser.
Other free tools
- SPF, DKIM and DMARC checkCan someone send email that looks like it came from your business?
- Security headers checkWhich protections does your homepage ask the browser for? Graded A to F.
- Cookies before consent checkDoes your site set cookies or load Google Analytics and Meta Pixel before anyone clicks accept?
The full scan runs 20+ checks in about 90 seconds.
Free, no account. You get a plain-language report and a brief for your developer.
Go to the full scan