DevToolsForYou
Private by defaultRuns in your browser

SSL certificate checker

Enter a domain to fetch and inspect its live SSL/TLS certificate — including the full chain from end-entity to root CA.

Quick samples
SSL Checker

About this tool

A browser trusts a certificate only if every link in a chain holds. The server presents its own leaf certificate along with any intermediates; those must chain up to a root the client already trusts, every certificate must be within its validity window, the hostname must match a Subject Alternative Name, and none may be revoked. A failure anywhere shows the user a full-page interstitial, which is the most expensive kind of outage because it looks like a security incident to everyone who sees it. Two failures dominate in practice: expiry, and a missing intermediate. Expiry is now a frequent risk because certificate lifetimes keep shrinking — Let's Encrypt issues for 90 days, the CA/Browser Forum is reducing maximum lifetimes further, and any process depending on someone remembering will eventually fail. A missing intermediate is more insidious, because desktop browsers often cache intermediates from previous sites and appear fine while mobile clients and API consumers fail. This tool fetches the live certificate chain for a domain and reports validity dates, issuer, Subject Alternative Names, fingerprints, and key details for each certificate in the chain.

No signup requiredRuns in your browserInstant results
How to use
  1. 1

    Enter a domain name (e.g. github.com) in the input field.

  2. 2

    Click Check — the tool fetches the live SSL/TLS certificate from the server.

  3. 3

    Review the certificate's validity period, issuer, and Subject Alternative Names.

  4. 4

    Expand each certificate in the chain to inspect intermediate and root CA details.

Why use this tool?
  • →

    Verify that a certificate covers all the expected subdomains via Subject Alternative Names.

  • →

    Check how many days are left before a certificate expires so you can renew before downtime.

  • →

    Inspect the full certificate chain to diagnose intermediate CA or trust issues.

ExamplesInput → output

Check expiry

Inputgithub.com
OutputValid until 2026-03-12 — 340 days remaining

Check SANs

Inputgoogle.com
OutputCovers: *.google.com, google.com, *.googleapis.com, ...

Inspect issuer

Inputdevtoolsforyou.com
OutputIssued by: Let's Encrypt R11 (3-cert chain)
Common errorsAnd how to fix them

The certificate is valid but the browser reports a name mismatch

Cause: The hostname is not listed in the Subject Alternative Name extension. A certificate for example.com does not cover www.example.com unless both are named, and a single-level wildcard does not cover a deeper subdomain.

Fix: Check the SAN list in the result and reissue with every hostname you serve. Modern clients ignore the Common Name field entirely — only SANs count.

It works in my browser but fails from curl or a mobile app

Cause: An incomplete chain. The server is not sending the intermediate certificate, and your browser happens to have cached it from another site while other clients have not.

Fix: Configure the server to send the full chain — leaf plus intermediates, excluding the root. Most web servers expect a single concatenated file with the leaf first.

A renewed certificate is not being served

Cause: The new file is on disk but the process holding the old one in memory was never reloaded, or a load balancer or CDN in front of the origin is serving its own cached certificate.

Fix: Reload the web server after renewal and make renewal hooks part of the automation. Where a CDN terminates TLS, the certificate that matters is the one configured there, not the one on your origin.

Frequently asked questionsCommon questions answered

These answers explain common ssl checker tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.

What is a certificate chain?

A certificate chain links your domain's end-entity certificate to a trusted root CA through one or more intermediate certificates. All links must be valid and trusted for browsers to accept the connection.

What are Subject Alternative Names (SANs)?

SANs are the list of domain names and subdomains a certificate is valid for. Modern certificates use SANs instead of the Common Name (CN) field, and a single certificate can cover hundreds of domains.

What does the SHA-256 fingerprint tell me?

The SHA-256 fingerprint is a unique hash of the certificate's content. You can use it to verify that the certificate you're seeing is exactly the one you expect — useful for certificate pinning and security audits.