Menu

SSL / TLS Checker

Results are based on a simulated check. For full certificate validation, use a dedicated service like SSL Labs.

SSL / TLS Checker: How It Works

An SSL/TLS check tells you whether a site's certificate is valid, who issued it, when it expires, and whether the chain is complete. Most certificate errors visitors encounter come from three causes, and all three are visible in a check like this.

What a certificate proves

A certificate binds a public key to a domain name, vouched for by a certificate authority the browser already trusts. It establishes that you are talking to the holder of that domain's private key, and it enables the encrypted connection.

What it does not prove is that the site is honest. A phishing site can obtain a valid certificate for its own domain in minutes. The padlock means 'this connection is private and the domain is what it claims' — not 'this site is trustworthy'.

The three common failures

ErrorCause
ExpiredRenewal missed — the most common outage of all
Name mismatchCertificate covers example.com but not www.example.com
Incomplete chainIntermediate certificate not installed on the server

The incomplete chain is the most confusing, because it often works in one browser and fails in another. Some clients cache intermediates from previous visits to other sites and appear to succeed; others do not and fail. A site that 'works on my machine' but fails for users is very often this.

Validation levels

TypeVerifiesIssued in
Domain Validated (DV)Control of the domainMinutes, usually free
Organisation Validated (OV)Domain plus organisation identityDays
Extended Validation (EV)Extensive legal verificationWeeks

Browsers stopped displaying special indicators for EV certificates several years ago, after research found users did not notice or act on them. Encryption strength is identical across all three; only the vetting differs. For most sites a free DV certificate is entirely appropriate.

Expiry and automation

Maximum certificate lifetimes have been shortened repeatedly and continue to fall. Manual renewal is no longer practical: automate issuance and renewal with ACME, and monitor expiry independently of the renewal process. Renewal at roughly two-thirds of the lifetime leaves room for a failure to be noticed and fixed before anything breaks.

What else to check

Frequently Asked Questions

What does the padlock actually mean?
That the connection is encrypted and the certificate matches the domain. It says nothing about whether the site is honest — phishing sites obtain valid certificates for their own domains routinely.
Why does my certificate work in one browser and fail in another?
Almost always a missing intermediate certificate. Some browsers cache intermediates from earlier visits and succeed anyway; others do not. Install the full chain on the server rather than relying on client caching.
Is a paid certificate more secure than a free one?
No. The encryption is identical. Paid certificates differ in the level of identity verification performed and in any warranty or support offered — not in cryptographic strength.
How often do certificates need renewing?
Maximum lifetimes have been shortened repeatedly and continue to fall, which makes automated renewal via ACME the only practical approach. Renew at around two-thirds of the lifetime and monitor expiry separately from the renewal job.
What is a name mismatch error?
The certificate does not cover the hostname being visited — commonly it covers example.com but not www.example.com. Include every hostname you serve in the certificate's subject alternative names.
Should I still support older TLS versions?
No. TLS 1.0 and 1.1 are deprecated, disabled by all current browsers, and prohibited by most compliance regimes. Serve TLS 1.2 and 1.3 only.

Related Security Tools

Browse all Security tools →