🔒 SSL Certificate Checker

Check the SSL/TLS certificate history for any domain — issuer, validity dates, days remaining, common name, and SANs — sourced live from public Certificate Transparency logs. Free, browser-only, no signup.

Examples: github.com   cloudflare.com   wikipedia.org
🕒 Recent Lookups
No recent lookups yet.

📚 What Is an SSL/TLS Certificate?

An SSL/TLS certificate is a digitally signed file that binds a public key to a domain name, issued by a trusted Certificate Authority (CA) after verifying the requester controls that domain. It powers HTTPS: encrypting traffic between browser and server, and proving to visitors that they're actually talking to the real site rather than an impersonator.

This tool reads that history from Certificate Transparency (CT) logs — public, append-only, cryptographically verifiable logs that every CA must publish issued certificates to for their certificates to be trusted by Chrome and other major browsers. That means you can see every certificate ever issued for a domain, not just the one currently live.

📋 Certificate Fields Explained

FieldMeaning
Common Name (CN)The primary hostname the certificate was issued for
SANEvery additional hostname the certificate secures — browsers check this list, not just CN
IssuerThe Certificate Authority that signed and issued the certificate
Not BeforeDate the certificate becomes valid
Not AfterExpiry date — the certificate is invalid after this date
Serial NumberUnique identifier assigned by the issuing CA

⚠️ What Certificate Transparency Logs Don't Show — and How This Tool Now Covers That Gap

Certificate Transparency logs record issuance, not the live server handshake — they can't tell you which TLS versions or cipher suites a server actually negotiates right now, because that information only exists in a live connection. Browsers also can't perform that live handshake introspection from JavaScript; there's no browser API that exposes negotiated cipher suite or protocol version back to a webpage, even for a page connecting to its own domain. Running the check yourself, from a terminal, is the only way to get a genuine live answer.

That's what the Test Live TLS Version & Cipher Support section above generates: ready-to-run openssl, nmap, and testssl.sh commands for whatever domain you just checked, so a single lookup here gives you both the certificate's issuance history and a direct path to checking its live configuration, without needing to remember the right flags yourself. For HSTS status and an overall grade alongside this, pair it with our Security Headers Checker.

💡
ToolsNovaHub Pro Tip
Run the TLS 1.0 and TLS 1.1 commands specifically expecting them to fail — a hardened, modern server should refuse those handshakes outright. If either one succeeds, that's a concrete, actionable finding: those protocol versions should be disabled in your server's TLS configuration.
⚠️
Common Beginner Mistake
Running these commands against a domain behind a CDN or load balancer and assuming the result reflects your origin server's configuration. Many CDNs terminate TLS at the edge with their own settings, independent of whatever your actual backend server supports — the result you get is the edge's configuration, not necessarily your own.

🔧 Troubleshooting

⚠️ Certificate shows expired but the site loads fine in your browser
Your browser may be caching an OCSP/session result, or the server presented a different certificate (e.g. via SNI) than the one this tool queried — try a hard refresh and re-check.
⚠️ "Certificate chain incomplete" warning
The server isn't sending its intermediate certificate(s), only the leaf. Most browsers tolerate this via AIA fetching, but some clients (mail servers, older devices, curl without -k) will hard-fail — fix by configuring the server to serve the full chain.
⚠️ Hostname mismatch
The certificate's Common Name/SAN list doesn't include the hostname you checked — common after a domain migration where the certificate wasn't reissued, or when checking a subdomain not covered by a non-wildcard cert.
⚠️ Renewed the certificate but this tool still shows the old one
Some CDNs and load balancers serve a cached certificate to a subset of edge nodes for a period after renewal — re-check after a few minutes, and from a different network if possible. Pair this check with our Security Headers Checker for a fuller picture of your site's transport security.

🛡️ Use Cases

⏳
Expiry Monitoring
Quickly see the most recent certificate's expiry date and days remaining before renewing manually or auditing an automated renewal pipeline.
🔍
Subdomain Discovery
SAN lists on wildcard and multi-domain certificates often reveal subdomains you didn't know existed — useful for security audits and attack-surface mapping.
🔐
Issuer Verification
Confirm certificates are coming from your expected CA. An unexpected issuer in the CT history can indicate a misconfiguration or, rarely, unauthorized issuance.
📈
Migration Verification
After moving hosting or CDN providers, confirm the new certificate has been issued and covers all required hostnames before cutting over DNS.

🔗 More Ways to Investigate Domain Security

Check response security headers with Security Headers Checker, confirm DNS setup with DNS Lookup, and verify email authentication with SPF Lookup and DKIM Lookup. Renewing or requesting a new certificate from scratch? Our CSR Generator builds the Certificate Signing Request and private key entirely in your browser, and the Certificate Decoder reads the field-by-field structure of a certificate you already have. Read our guides: What Is SSL/TLS? and How to Fix an Expired SSL Certificate.

ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.

🎓
Expert Tip
A single scan from SSL Certificate Checker is a snapshot — security posture drifts as certificates near expiry or headers get overwritten by a new deploy, so schedule periodic re-checks.
⭐
ToolsNovaHub Pro Tip
Combine SSL Certificate Checker with our Website Security Scanner for one combined view covering TLS, headers, and email authentication together.
⚠️
Common Beginner Mistake
Assuming a perfect score from SSL Certificate Checker means the site is fully secure. It checks configuration, not application-layer bugs like SQL injection — pair it with a manual code review.

📋 Related Tools & Guides Comparison

ResourceTypeLink
Blacklist CheckSecurityOpen Tool →
Security Headers CheckerSecurityOpen Tool →
Website Security ScannerSecurityOpen Tool →
Common Website Vulnerabilities Checklist: What to Check & FixGuideRead Guide →
How to Fix an Expired SSL Certificate (Step-by-Step Guide)GuideRead Guide →

FAQ

An SSL/TLS certificate is a digitally signed file that binds a public key to a domain name, issued by a trusted Certificate Authority (CA) after verifying the requester c…
Yes, SSL Certificate Checker is free to use • no account required, and no hidden charges. It queries a third-party provider live, so usage is subject to that provider's own rate limits under heavy or automated use, not a cap we impose.
It queries public Certificate Transparency logs, which every CA must publish issued certificates to for browser trust. This reveals every certificate ever issued for a domain without contacting the server directly.
CT (RFC 9162) requires CAs to log every issued certificate to public, append-only, tamper-evident logs. Chrome and other browsers require CT compliance for a certificate to be trusted.
Certificates typically last 90–398 days and get reissued repeatedly. Wildcard and multi-SAN certificates, plus staging/production splits, also multiply the count shown.
Days until the most recent certificate's Not After date. Past that, browsers block the site with a certificate-expired warning by default.
Subject Alternative Name — every hostname a certificate is valid for. Browsers require the visited hostname to appear in SAN, not just match the Common Name.
Let's Encrypt is the largest, issuing short-lived 90-day DV certificates automatically via ACME. ZeroSSL, Google Trust Services, DigiCert, Sectigo, and Amazon are also common in CT logs.
DV only confirms domain control. OV additionally verifies the organization is real. EV requires the most rigorous vetting. Modern browsers show all three identically in the address bar.
The Certificate Transparency lookup itself shows issuance history, not the live handshake, cipher suites, or protocol version. After each lookup, this tool also generates ready-to-run openssl, nmap, and testssl.sh commands so you can check the live configuration yourself in a terminal — browsers don't expose that data to JavaScript directly, so a real terminal command is the only way to get a genuine live result.
Browser JavaScript has no API that exposes the negotiated TLS version or cipher suite from a connection, even for a page's own domain, so a live TLS check has to happen through a terminal command rather than entirely inside the browser.
The openssl commands attempt a handshake using one specific TLS version each, revealing which versions the server accepts or rejects. The nmap command enumerates every cipher suite the server supports across all its accepted protocol versions in a single scan.
Either no publicly trusted certificate exists, it uses a private CA outside CT scope, or the hostname is only covered by a wildcard on the parent domain — try the root domain instead.
Yes. CT logs are public by design specifically so certificate issuance is auditable by anyone, not just the domain owner.
A certificate like *.example.com that secures the base domain plus every direct first-level subdomain — it won't cover multi-level subdomains like a.b.example.com.
With Let's Encrypt/Certbot, renewal is usually automatic via cron/systemd — verify it's running. For commercial CAs, reissue via your provider's dashboard before expiry.
Yes — completely free, no sign-up, and we don't cap normal usage. Results are pulled live from public Certificate Transparency log search services, which may themselves rate-limit unusually heavy or automated traffic.