TLS certificate
Issuer, expiry, validity and remaining time from the live certificate handshake. Free, no signup, 5 checks a day.
You can open any section directly with a domain in the URL query string, then share that result page with someone else.
How to read this result
These notes explain what the check is showing, where the data comes from and what the main blind spots are.
What the check reads
The certificate is fetched in a live handshake on port 443: who issued it, when it expires, how many days remain, and whether it validates. The answer is what browsers actually get, not what a control panel claims.
The 30-day renewal rule
Automated renewal usually fires at 30 days remaining. Under 14 days is flagged amber here, and anything already past its date is red — an expired certificate has usually been failing quietly for a while, because renewals break silently more often than anyone expects.
Wildcard certificates
A *.domain certificate covers every host under the name without ever naming one, so individual hostnames stop reaching public certificate logs. That hides subdomains from passive discovery — it is a blind spot, not a breach.
What the error column means
No answer means the port refused the handshake or the name carries no certificate at all. A refused connection is a server configuration question, not a certificate one, and it is reported as such.