SSL expiry checker
This SSL expiry checker reads the certificate your server presents right now and tells you the exact expiry date and the days remaining. It checks the live connection, so a renewal that ran but never reloaded is caught too. No signup.
Free instant check. No signup, no email, no crawler — we read the certificate your server presents to real visitors.
What the check covers
The real expiry date
Read from the certificate your server serves on a live connection. If your cron renewed the certificate but the web server never reloaded it, visitors still get the old one, and this check shows it.
Days remaining, at a glance
The date and a countdown. Under 14 days shows as a warning, expired shows in red with how long ago it lapsed.
Why this matters more now
Let's Encrypt stopped sending expiry emails in June 2025, and certificate lifetimes are dropping toward 47 days by 2029. More renewals, less warning. Checking by hand does not scale past one certificate.
Alerts before it happens
CertPost can watch the certificate and email you at 30, 14, 7, and 1 days before expiry, plus a webhook if you want it in Slack or PagerDuty. Free for up to 3 certificates.
Common questions
How do I check when my SSL certificate expires?
Paste your domain into the checker above. It connects to your server, reads the certificate presented, and shows the exact expiry date and days remaining. This is the certificate your visitors receive, not what a renewal log claims.
Can I get an alert before my SSL certificate expires?
Yes. A free CertPost account monitors up to 3 certificates daily and emails you at 30, 14, 7, and 1 days before expiry. Paid plans check more certificates, more often, with webhook alerts for Slack and PagerDuty.
Why did I stop getting Let's Encrypt expiry emails?
Let's Encrypt ended expiration notification emails on 4 June 2025. If you relied on those, nothing warns you now unless you run your own monitoring.
My certificate auto-renews. Do I still need to check?
Yes. Auto-renewal fails silently more often than people expect: a changed DNS record, a firewall rule, a rate limit, or a web server that renewed on disk but never reloaded. The only reliable signal is checking what the server actually serves.