DevOps

SSL Certificate Checker

See exactly what certificate a website serves โ€” who issued it, when it expires, which names it covers and whether browsers trust it โ€” plus clear steps to fix anything that's wrong.

A domain or a full URL โ€” we connect to it on port 443 (HTTPS) and read the certificate it presents.

Try:

The badssl.com examples are deliberately broken test sites โ€” handy to see what problems look like.

Enter a domain to check its SSL/TLS certificate.

  • Expiry at a glance

    Valid-from and expiry dates, days remaining and a warning when renewal is due within 30 days.

  • Real trust checks

    Verifies the chain against trusted root certificates and checks the certificate actually covers the domain.

  • Fixes in plain English

    Missing intermediates, name mismatches, weak keys and missing HSTS โ€” each with what to do next.

How this SSL checker works

When you press Check, AISeekho's server opens a secure connection to the domain on port 443, exactly like a browser would, and reads the certificate the server presents. It doesn't send any page request over that connection โ€” it only completes the handshake. A separate request for the home page reads the Strict-Transport-Security (HSTS) header.

What it checks

  • Validity dates: when the certificate starts and expires, and how many days are left.
  • Chain of trust:whether the certificate leads to a root that browsers trust, and why not if it doesn't (self-signed, missing intermediate, expired, revoked).
  • Hostname match:whether the certificate's names cover the exact domain you entered. A wildcard like *.example.com covers one level only.
  • Connection details: TLS version, cipher, key type and size, and HTTP/2 support.
  • Identifiers: serial number and SHA-256 fingerprint, useful when comparing certificates.

Tips

  • Free certificates from Let's Encrypt last 90 days โ€” make sure automatic renewal is running, then check again after the next renewal.
  • "Incomplete chain" errors usually mean the server is configured with cert.pem instead of fullchain.pem.
  • Use at least a 2048-bit RSA or 256-bit ECDSA key.

Only public domain names on the standard HTTPS port can be checked โ€” IP addresses, localhost and private network addresses are rejected.

How this works. This tool runs on AISeekho's server because a browser can't do it on its own. We don't store what you enter.