SSL CERTIFICATE
</>BrowserClientTLS HandshakeSVRServer
Status
—
Issuer
—
Days Left
—

This tool connects to a domain over HTTPS and retrieves its SSL/TLS certificate. It shows the certificate issuer, validity period, protocol version, and alternative names. If a certificate is expired, misconfigured, or missing, visitors will see browser security warnings — checking your certificate regularly helps prevent that.

What Is an SSL Certificate?

An SSL (Secure Sockets Layer) certificate is a digital credential that authenticates a website's identity and enables encrypted communication between the browser and the server. When you see the padlock icon in your browser's address bar, it means the site has a valid SSL certificate and your connection is encrypted.

Modern certificates actually use TLS (Transport Layer Security), the successor to SSL, but the term “SSL” is still widely used. TLS provides stronger encryption algorithms and improved handshake protocols compared to the original SSL specification.

SSL certificates are issued by Certificate Authorities (CAs) — trusted organizations that verify the identity of the certificate applicant before issuing the credential. Browsers ship with a list of trusted CAs, and any certificate signed by one of these authorities is automatically trusted by the browser.

Why SSL Certificates Matter

  • Encryption — SSL prevents third parties from reading data transmitted between the browser and server. This protects passwords, credit card numbers, and personal information from eavesdropping.
  • Trust — Browsers display warnings for sites without valid SSL, driving visitors away. A valid certificate signals that the site is legitimate and safe to interact with.
  • SEO — Google uses HTTPS as a ranking signal — sites with SSL may rank higher in search results. Migrating from HTTP to HTTPS can provide a small but meaningful boost in organic visibility.
  • Compliance — Many regulations (PCI DSS, HIPAA) require encrypted connections for handling sensitive data. Without SSL, your site may fail compliance audits and face penalties.

Understanding Certificate Details

  • Issuer — The Certificate Authority (CA) that issued the certificate (e.g., Let's Encrypt, DigiCert, Sectigo). The issuer vouches for the identity of the certificate holder.
  • Subject — The domain name(s) the certificate was issued for. The browser checks that the domain you are visiting matches the subject of the certificate.
  • Valid From / Valid To — The certificate's validity window — connections outside this window trigger browser warnings. Most certificates are valid for 90 days to 1 year.
  • Days Remaining — How many days until the certificate expires — renew before this reaches zero. Automated renewal tools like Certbot can handle this for Let's Encrypt certificates.
  • Protocol — The TLS version negotiated (TLS 1.2 or 1.3 are current standards; older versions are insecure). TLS 1.3 offers faster handshakes and stronger security guarantees.
  • Subject Alternative Names (SANs) — Additional domain names covered by the same certificate. A single certificate can protect multiple domains and subdomains through SANs.

Learn More

Read our in-depth guide to understand the concepts behind this tool:

  • What Is SSL/TLS? — How encryption works, certificate types, the TLS handshake, and best practices.

Frequently Asked Questions

How often should I check my SSL certificate?

Check at least monthly, and set up monitoring for automatic expiry alerts. Certificates from Let's Encrypt expire every 90 days; commercial certificates typically last 1 year. An expired certificate immediately triggers browser warnings that will drive visitors away.

What does “certificate not trusted” mean?

This means the certificate was not issued by a recognized Certificate Authority, the certificate chain is incomplete, or the certificate has been revoked. Self-signed certificates also trigger this warning. To fix it, obtain a certificate from a trusted CA like Let's Encrypt (free) or a commercial provider.

Is TLS the same as SSL?

TLS (Transport Layer Security) is the modern successor to SSL (Secure Sockets Layer). SSL is technically deprecated — all current “SSL certificates” actually use TLS. The term SSL persists in common usage. TLS 1.2 and 1.3 are the current standards; TLS 1.0 and 1.1 are considered insecure.

Does this tool test my site from the outside?

Yes. This tool connects to your domain from our server over port 443 (HTTPS) and retrieves the certificate exactly as a visitor's browser would. This gives you an external perspective on what your visitors see.