See the SSL/TLS certificates issued for any domain, read from the public Certificate Transparency logs — the issuer, the expiry date, and every hostname each certificate covers. Free, instant, no signup.
How to check a certificate
- Enter a domain or hostname (e.g.
example.com). - Press Check.
- Read the most recent certificate — its issuer, validity dates, days-until-expiry, and the names it covers — plus a list of other recently-issued certificates.
What this checks — read this first
This tool reads Certificate Transparency (CT) logs, the public, append-only logs that every publicly-trusted certificate authority is required to submit issued certificates to. That makes it excellent for answering:
- When does my certificate expire? (and is a renewal overdue?)
- Who issued it, and what hostnames does it cover?
- Has any certificate been issued for my domain that I didn’t request? — the security use case CT was built for.
What it cannot do — stated plainly — is read the certificate a server presents in a live TLS
handshake. That requires a raw TLS connection, which this tool’s serverless backend can’t open. So
it shows what was issued (from the logs), not a live confirmation of what’s deployed right
now. The latest-expiring certificate is almost always the active one, but if you must verify the
live handshake, reach for openssl s_client or your browser’s certificate viewer.
Reading the expiry
The most recent certificate leads with a color-coded countdown: green with comfortable time left, amber under 30 days, and red under two weeks or already expired. Short lifetimes are normal and healthy — Let’s Encrypt certificates last 90 days and renew automatically — so an amber badge on an auto-renewing site usually isn’t cause for alarm. A red or expired badge on a site you manage is worth investigating.
Private by design
The check runs server-side against the public crt.sh logs; we don’t store the hostnames you check. Pair it with the WHOIS lookup for registration and renewal dates, the DNS lookup to see where the domain points, and what is my IP for your own connection.