Skip to content
TNToolsNexus

SSL certificate checker

Check the SSL/TLS certificates issued for any domain from public Certificate Transparency logs — issuer, expiry date, and covered hostnames. Free, no signup.

The check runs through our server against public Certificate Transparency logs (crt.sh); we don't store the hostnames you check.

See the SSL/TLS certificates issued for any domain, read from the public Certificate Transparency logs — the issuer, the expiry date, and every hostname each certificate covers. Free, instant, no signup.

How to check a certificate

  1. Enter a domain or hostname (e.g. example.com).
  2. Press Check.
  3. Read the most recent certificate — its issuer, validity dates, days-until-expiry, and the names it covers — plus a list of other recently-issued certificates.

What this checks — read this first

This tool reads Certificate Transparency (CT) logs, the public, append-only logs that every publicly-trusted certificate authority is required to submit issued certificates to. That makes it excellent for answering:

  • When does my certificate expire? (and is a renewal overdue?)
  • Who issued it, and what hostnames does it cover?
  • Has any certificate been issued for my domain that I didn’t request? — the security use case CT was built for.

What it cannot do — stated plainly — is read the certificate a server presents in a live TLS handshake. That requires a raw TLS connection, which this tool’s serverless backend can’t open. So it shows what was issued (from the logs), not a live confirmation of what’s deployed right now. The latest-expiring certificate is almost always the active one, but if you must verify the live handshake, reach for openssl s_client or your browser’s certificate viewer.

Reading the expiry

The most recent certificate leads with a color-coded countdown: green with comfortable time left, amber under 30 days, and red under two weeks or already expired. Short lifetimes are normal and healthy — Let’s Encrypt certificates last 90 days and renew automatically — so an amber badge on an auto-renewing site usually isn’t cause for alarm. A red or expired badge on a site you manage is worth investigating.

Private by design

The check runs server-side against the public crt.sh logs; we don’t store the hostnames you check. Pair it with the WHOIS lookup for registration and renewal dates, the DNS lookup to see where the domain points, and what is my IP for your own connection.

Last updated:

Frequently asked questions

What does this SSL checker actually check?
It reads the public Certificate Transparency (CT) logs via crt.sh to show the SSL/TLS certificates that have been issued for a hostname — the issuer (certificate authority), the validity window, when the current one expires, and every domain name the certificate covers. Every publicly-trusted certificate is required to be logged, so this is a reliable record of what was issued.
Does it check the certificate my server is serving right now?
No — and this is the honest limitation. Reading the live certificate a server presents needs a raw TLS handshake, which this tool's serverless backend cannot make. So it shows certificates that were issued for the hostname (from CT logs), not proof of which one is deployed at this moment. In practice the certificate with the latest expiry is almost always the active one, but if you need to confirm the live handshake, use a command-line tool like openssl.
How do I read the expiry status?
The most recent certificate shows days until it expires, color-coded: green when there is comfortable time, amber under 30 days, and red when it is under two weeks or already expired. Certificates typically last 90 days (Let's Encrypt) up to about a year, and are usually renewed automatically well before expiry.
Why do I see several certificates for one domain?
That is normal. Certificates are reissued on every renewal, and a domain may use more than one certificate authority or cover different subdomains with different certificates. The list is sorted so the latest-expiring one — the likely current cert — is on top.
It says no certificates were found — what does that mean?
Either the hostname is new (a freshly-issued certificate can take a short while to appear in the logs), it is an internal host that was never issued a publicly-trusted certificate, or it uses a certificate that was not logged. It does not necessarily mean the site is insecure.
Can I use this to catch mis-issued certificates?
Yes — that is exactly what Certificate Transparency was designed for. If you own a domain, scanning its CT log entries lets you spot a certificate you did not request, which can be an early sign of a compromise or a mistaken issuance. Seeing every certificate ever issued for your domain is a genuine security control.

Related tools

DNS Lookup

Look up DNS records for any domain — A, AAAA, MX, TXT, NS, and CNAME — over encrypted DNS-over-HTTPS, with TTLs and values in a clean table. Free, no signup.

WHOIS Lookup

Check a domain’s registration: registrar, creation and expiry dates, name servers, and status codes — from the official RDAP registry data. Free and instant.

What Is My IP Address

See your public IP address (IPv4 or IPv6) instantly, plus your approximate location, timezone, and network provider — read from your own request, not stored.