SSL certificate expiry checker

Days until expiry, chain validity, hostname match and weak signatures. Free, no signup.

Public hostnames only. A few checks a minute.

What this actually checks

Most expiry checkers tell you a date. The useful part is everything around it — a certificate can be years from expiring and still be broken for half your visitors.

This reports expiry in days (negative once past), whether the hostname is really covered using proper wildcard matching rather than a string comparison, whether the chain terminates in a publicly trusted root, whether the server actually sent its intermediates, the signature algorithm anywhere below the root, key strength, and the TLS version that was negotiated.

The one that catches people out

A missing intermediate. Your browser has probably cached that intermediate certificate from some other site, so the page loads perfectly for you — and fails in curl, in Java, and on a phone that has never seen it. It is the classic "works on my machine" TLS bug, and a checker that only looks at the leaf certificate will not see it.

Why the handshake is allowed to complete

This tool deliberately does not let the TLS library reject a bad certificate. If it did, you would get an exception and nothing else — but a bad certificate is the entire reason you are here. "Expired four days ago, issued by Let's Encrypt, covers these three names" is an answer. "Connection failed" is what you already knew.

Need this for more than one domain?

The same checks are available as an API — a hundred domains per call, with days_remaining as a top-level field so a monitor can alert on it without parsing anything. See the API on RapidAPI.