FreeNo signup, no email

Free SSL checker

Paste a domain into the SSL checker below and it reads the certificate your server presents on a live TLS connection. You see the expiry date, the issuer, whether the full chain is valid, whether the hostname matches, and an A to F grade of the TLS configuration. No signup, no email.

Free instant check. No signup, no email, no crawler — we read the certificate your server presents to real visitors.

What the check covers

The served certificate, not the renewal log

The check opens a real TLS connection and reads what your server sends. A renewal that succeeded on disk but was never reloaded still shows up as the old certificate, because that is what your visitors receive.

Expiry, issuer, and hostname

The expiry date with days remaining, who issued the certificate, every hostname the certificate covers, and whether it matches the domain you checked.

The full chain

Leaf, intermediates, and root are validated together. An expired intermediate breaks visitors even when your own certificate is fine. That is the failure that took down thousands of sites when the AddTrust root expired.

A TLS grade

Protocol versions, cipher strength, key strength, and HSTS, graded A to F with a plain-English finding behind every deduction.

Common questions

Is this SSL checker free?

Yes. The check runs without an account, an email address, or a card. An account is only needed if you want CertPost to keep checking the certificate and alert you before it expires.

What does the SSL checker actually test?

It opens a TLS connection to your server and reads the certificate presented: expiry date, issuer, the full chain including intermediates, hostname and SAN match, protocol versions, and cipher configuration. It checks what your visitors receive, not what your renewal tooling reports.

Can I check a port other than 443?

Yes. Use host:port syntax, e.g. mail.example.com:465. The checker works on any TLS port — SMTP, IMAPS, LDAPS, or an admin panel on 8443.

How is this different from SSL Labs?

SSL Labs grades TLS configuration in depth and takes a minute or two per scan. This check answers the operational questions in seconds — is the certificate valid, when does it expire, is the chain intact — and grades the TLS configuration the same A to F way. CertPost can then monitor the certificate so you hear about problems before visitors do.

Monitor this certificate free