Network & DNS

SSL Certificate Checker

Check the TLS certificate on a public host. See the issuer, the expiry date, and how many days are left.

Results appear here.

What the result means

This check opens a TLS connection to port 443 on the public host you name and reads the certificate that host presents. It does not call a certificate directory, and it does not invent dates. Issuer, not before, and not after come from that peer certificate. Days left is the number of whole days until not after. A warning appears when fewer than 14 days remain, including a date that is already past. If the handshake fails, the page shows the error and leaves the dates blank. A self-signed certificate can still be read, and the result says so instead of hiding it. Private, loopback, and link-local hosts are refused before the connection. The dates are what that host presents to Cloudflare's edge.

Related tools

Advertisement

Questions

Can this see a self-signed certificate?

Yes. The handshake is read even when the certificate is not trusted. The result says the certificate is self-signed and still shows the issuer and the dates.

Why is the expiry missing?

The dates are missing only when the handshake did not produce a certificate. The page shows that error and does not fill in a guess.

Does this use a paid certificate database?

No. The Worker reads the certificate from the connection to port 443. It does not call an outside certificate API.