📚 What Is an SSL/TLS Certificate?
An SSL/TLS certificate is a digitally signed file that binds a public key to a domain name, issued by a trusted Certificate Authority (CA) after verifying the requester controls that domain. It powers HTTPS: encrypting traffic between browser and server, and proving to visitors that they're actually talking to the real site rather than an impersonator.
This tool reads that history from Certificate Transparency (CT) logs — public, append-only, cryptographically verifiable logs that every CA must publish issued certificates to for their certificates to be trusted by Chrome and other major browsers. That means you can see every certificate ever issued for a domain, not just the one currently live.
📋 Certificate Fields Explained
⚠️ What Certificate Transparency Logs Don't Show — and How This Tool Now Covers That Gap
Certificate Transparency logs record issuance, not the live server handshake — they can't tell you which TLS versions or cipher suites a server actually negotiates right now, because that information only exists in a live connection. Browsers also can't perform that live handshake introspection from JavaScript; there's no browser API that exposes negotiated cipher suite or protocol version back to a webpage, even for a page connecting to its own domain. Running the check yourself, from a terminal, is the only way to get a genuine live answer.
That's what the Test Live TLS Version & Cipher Support section above generates: ready-to-run openssl, nmap, and testssl.sh commands for whatever domain you just checked, so a single lookup here gives you both the certificate's issuance history and a direct path to checking its live configuration, without needing to remember the right flags yourself. For HSTS status and an overall grade alongside this, pair it with our Security Headers Checker.
💡
ToolsNovaHub Pro Tip
Run the TLS 1.0 and TLS 1.1 commands specifically expecting them to fail — a hardened, modern server should refuse those handshakes outright. If either one succeeds, that's a concrete, actionable finding: those protocol versions should be disabled in your server's TLS configuration.
⚠️
Common Beginner Mistake
Running these commands against a domain behind a CDN or load balancer and assuming the result reflects your origin server's configuration. Many CDNs terminate TLS at the edge with their own settings, independent of whatever your actual backend server supports — the result you get is the edge's configuration, not necessarily your own.
🔧 Troubleshooting
⚠️ Certificate shows expired but the site loads fine in your browser
Your browser may be caching an OCSP/session result, or the server presented a different certificate (e.g. via SNI) than the one this tool queried — try a hard refresh and re-check.
⚠️ "Certificate chain incomplete" warning
The server isn't sending its intermediate certificate(s), only the leaf. Most browsers tolerate this via AIA fetching, but some clients (mail servers, older devices, curl without -k) will hard-fail — fix by configuring the server to serve the full chain.
⚠️ Hostname mismatch
The certificate's Common Name/SAN list doesn't include the hostname you checked — common after a domain migration where the certificate wasn't reissued, or when checking a subdomain not covered by a non-wildcard cert.
⚠️ Renewed the certificate but this tool still shows the old one
Some CDNs and load balancers serve a cached certificate to a subset of edge nodes for a period after renewal — re-check after a few minutes, and from a different network if possible. Pair this check with our
Security Headers Checker for a fuller picture of your site's transport security.
🛡️ Use Cases
⏳
Expiry Monitoring
Quickly see the most recent certificate's expiry date and days remaining before renewing manually or auditing an automated renewal pipeline.
🔍
Subdomain Discovery
SAN lists on wildcard and multi-domain certificates often reveal subdomains you didn't know existed — useful for security audits and attack-surface mapping.
🔐
Issuer Verification
Confirm certificates are coming from your expected CA. An unexpected issuer in the CT history can indicate a misconfiguration or, rarely, unauthorized issuance.
📈
Migration Verification
After moving hosting or CDN providers, confirm the new certificate has been issued and covers all required hostnames before cutting over DNS.
🔗 More Ways to Investigate Domain Security
Check response security headers with Security Headers Checker, confirm DNS setup with DNS Lookup, and verify email authentication with SPF Lookup and DKIM Lookup. Renewing or requesting a new certificate from scratch? Our CSR Generator builds the Certificate Signing Request and private key entirely in your browser, and the Certificate Decoder reads the field-by-field structure of a certificate you already have. Read our guides: What Is SSL/TLS? and How to Fix an Expired SSL Certificate.
ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.
What Is an SSL/TLS Certificate? +
An SSL/TLS certificate is a digitally signed file that binds a public key to a domain name, issued by a trusted Certificate Authority (CA) after verifying the requester c…
Is SSL Certificate Checker free to use? +
Yes, SSL Certificate Checker is free to use • no account required, and no hidden charges. It queries a third-party provider live, so usage is subject to that provider's own rate limits under heavy or automated use, not a cap we impose.
How does this SSL Certificate Checker work? +
It queries public Certificate Transparency logs, which every CA must publish issued certificates to for browser trust. This reveals every certificate ever issued for a domain without contacting the server directly.
What is Certificate Transparency? +
CT (
RFC 9162) requires CAs to log every issued certificate to public, append-only, tamper-evident logs. Chrome and other browsers require CT compliance for a certificate to be trusted.
Why does a domain show multiple certificates? +
Certificates typically last 90–398 days and get reissued repeatedly. Wildcard and multi-SAN certificates, plus staging/production splits, also multiply the count shown.
What does days remaining mean? +
Days until the most recent certificate's Not After date. Past that, browsers block the site with a certificate-expired warning by default.
What is a SAN in an SSL certificate? +
Subject Alternative Name — every hostname a certificate is valid for. Browsers require the visited hostname to appear in SAN, not just match the Common Name.
Who are the major free SSL issuers? +
Let's Encrypt is the largest, issuing short-lived 90-day DV certificates automatically via ACME. ZeroSSL, Google Trust Services, DigiCert, Sectigo, and Amazon are also common in CT logs.
What is the difference between DV, OV, and EV certificates? +
DV only confirms domain control. OV additionally verifies the organization is real. EV requires the most rigorous vetting. Modern browsers show all three identically in the address bar.
Does this tool check my live TLS configuration? +
The Certificate Transparency lookup itself shows issuance history, not the live handshake, cipher suites, or protocol version. After each lookup, this tool also generates ready-to-run openssl, nmap, and testssl.sh commands so you can check the live configuration yourself in a terminal — browsers don't expose that data to JavaScript directly, so a real terminal command is the only way to get a genuine live result.
Why can't this tool show live TLS version and cipher support directly in the browser? +
Browser JavaScript has no API that exposes the negotiated TLS version or cipher suite from a connection, even for a page's own domain, so a live TLS check has to happen through a terminal command rather than entirely inside the browser.
What do the generated TLS commands actually test? +
The openssl commands attempt a handshake using one specific TLS version each, revealing which versions the server accepts or rejects. The nmap command enumerates every cipher suite the server supports across all its accepted protocol versions in a single scan.
Why is no certificate showing for my domain? +
Either no publicly trusted certificate exists, it uses a private CA outside CT scope, or the hostname is only covered by a wildcard on the parent domain — try the root domain instead.
Can I check certificate history for a domain I don't own? +
Yes. CT logs are public by design specifically so certificate issuance is auditable by anyone, not just the domain owner.
What is a wildcard SSL certificate? +
A certificate like *.example.com that secures the base domain plus every direct first-level subdomain — it won't cover multi-level subdomains like a.b.example.com.
How do I renew an expiring SSL certificate? +
With Let's Encrypt/Certbot, renewal is usually automatic via cron/systemd — verify it's running. For commercial CAs, reissue via your provider's dashboard before expiry.
Is this SSL Certificate Checker free? +
Yes — completely free, no sign-up, and we don't cap normal usage. Results are pulled live from public Certificate Transparency log search services, which may themselves rate-limit unusually heavy or automated traffic.