SSL certificate checker
Enter a domain to fetch and inspect its live SSL/TLS certificate — including the full chain from end-entity to root CA.
About this tool
A browser trusts a certificate only if every link in a chain holds. The server presents its own leaf certificate along with any intermediates; those must chain up to a root the client already trusts, every certificate must be within its validity window, the hostname must match a Subject Alternative Name, and none may be revoked. A failure anywhere shows the user a full-page interstitial, which is the most expensive kind of outage because it looks like a security incident to everyone who sees it. Two failures dominate in practice: expiry, and a missing intermediate. Expiry is now a frequent risk because certificate lifetimes keep shrinking — Let's Encrypt issues for 90 days, the CA/Browser Forum is reducing maximum lifetimes further, and any process depending on someone remembering will eventually fail. A missing intermediate is more insidious, because desktop browsers often cache intermediates from previous sites and appear fine while mobile clients and API consumers fail. This tool fetches the live certificate chain for a domain and reports validity dates, issuer, Subject Alternative Names, fingerprints, and key details for each certificate in the chain.
- 1
Enter a domain name (e.g. github.com) in the input field.
- 2
Click Check — the tool fetches the live SSL/TLS certificate from the server.
- 3
Review the certificate's validity period, issuer, and Subject Alternative Names.
- 4
Expand each certificate in the chain to inspect intermediate and root CA details.
Verify that a certificate covers all the expected subdomains via Subject Alternative Names.
Check how many days are left before a certificate expires so you can renew before downtime.
Inspect the full certificate chain to diagnose intermediate CA or trust issues.
Check expiry
github.comValid until 2026-03-12 — 340 days remainingCheck SANs
google.comCovers: *.google.com, google.com, *.googleapis.com, ...Inspect issuer
devtoolsforyou.comIssued by: Let's Encrypt R11 (3-cert chain)The certificate is valid but the browser reports a name mismatch
Cause: The hostname is not listed in the Subject Alternative Name extension. A certificate for example.com does not cover www.example.com unless both are named, and a single-level wildcard does not cover a deeper subdomain.
Fix: Check the SAN list in the result and reissue with every hostname you serve. Modern clients ignore the Common Name field entirely — only SANs count.
It works in my browser but fails from curl or a mobile app
Cause: An incomplete chain. The server is not sending the intermediate certificate, and your browser happens to have cached it from another site while other clients have not.
Fix: Configure the server to send the full chain — leaf plus intermediates, excluding the root. Most web servers expect a single concatenated file with the leaf first.
A renewed certificate is not being served
Cause: The new file is on disk but the process holding the old one in memory was never reloaded, or a load balancer or CDN in front of the origin is serving its own cached certificate.
Fix: Reload the web server after renewal and make renewal hooks part of the automation. Where a CDN terminates TLS, the certificate that matters is the one configured there, not the one on your origin.
These answers explain common ssl checker tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.
What is a certificate chain?
A certificate chain links your domain's end-entity certificate to a trusted root CA through one or more intermediate certificates. All links must be valid and trusted for browsers to accept the connection.
What are Subject Alternative Names (SANs)?
SANs are the list of domain names and subdomains a certificate is valid for. Modern certificates use SANs instead of the Common Name (CN) field, and a single certificate can cover hundreds of domains.
What does the SHA-256 fingerprint tell me?
The SHA-256 fingerprint is a unique hash of the certificate's content. You can use it to verify that the certificate you're seeing is exactly the one you expect — useful for certificate pinning and security audits.