What SSL Checker checks
- Validity period — when the certificate was issued, when it expires and how many days are left.
- Trust — whether system certificate authorities trust the certificate and whether the chain up to the root is complete.
- Name match — whether your domain is among the certificate’s names (SAN), including wildcards.
- Issuer and chain — who issued the certificate and which intermediate certificates the server sends.
- Security — signature algorithm, key length, TLS version and cipher.
- HSTS — whether the site requires being opened over https only.
Why you need to monitor an SSL certificate
An expired or misconfigured certificate instantly scares visitors away: the browser shows a full-screen security warning, while search bots and API clients simply refuse to connect. Let’s Encrypt certificates are valid for only 90 days, so automatic renewal has to work flawlessly, and a renewal failure is better noticed in advance.
Common SSL errors
SSL, TLS and HTTPS: what is the difference
SSL is the old name of the protocol that is now called TLS; the word SSL has stuck in everyday use. HTTPS is plain HTTP over TLS, and the certificate proves that you are connecting to your own site. Modern sites should run on TLS 1.2 and 1.3, and the old TLS 1.0 and 1.1 should be switched off. To see where the switch from http to https leads, use Redirect Checker.
Does SSL affect search rankings
Yes, though not by much: https has long been a Google ranking signal, and more importantly browsers flag http sites as unsafe, which scares visitors. An invalid certificate can shut a site off for users and bots altogether. Whether pages made it into search is checked by the page indexing check, and the domain’s DNS records are shown by DNS Lookup.
Limits of the check
We check the certificate on port 443 for the name you entered (SNI). A site behind a CDN may give us the delivery network’s certificate rather than your server’s. Internal and private addresses cannot be checked. Each subdomain has its own certificate, so check the host you need separately.
The HSTS header and other security headers are checked by HTTP Headers Checker.
What else StayIndexed can do
This page is a free tool from the StayIndexed service. In your account you can save a list of your sites, refresh the check in one click and see the certificate’s change history (also free), while the main job of the service is to track how your pages are doing in Google.
How much it costs
The check is free, both on this page and in your account. Tokens are used to pay for the other services: indexing, speed and backlinks cost 3 tokens per check. 30 tokens are credited at sign-up, no card required.
Frequently asked questions
How do I check a site’s SSL certificate?
Enter the domain in the form above: we will connect to port 443, read the certificate and show the expiry date, issuer, chain, TLS version and any errors found.
How long is an SSL certificate valid?
Public certificates are issued for at most 398 days, and Let’s Encrypt for only 90. So a certificate must be renewed regularly, ideally automatically.
What does a name mismatch error mean?
The domain you opened is not in the certificate’s list of names. A common cause: the certificate is issued for example.com while the site is opened as www.example.com. Add all the names you need.
Why does it work on a computer but fail on a phone?
Most likely the server does not send the intermediate certificate. Desktop browsers can fetch it, while mobile devices and API clients cannot. Set up the full chain (fullchain).
What is HSTS?
It is the Strict-Transport-Security header: it tells the browser to always open the site over https and does not let protection be bypassed. The recommended period is 180 days or more.
How much does an SSL check cost?
Nothing: the check is free both on this page and in your StayIndexed account. In your account you can save a list of sites, refresh the check in one click and see the history of certificate changes.