Free SSL Certificate Checker
Enter any domain to see when its SSL certificate expires — read live from the connection, instantly, with no signup.
Why SSL expiry catches people out
An SSL/TLS certificate is what puts the padlock in the address bar and encrypts traffic between your site and its visitors. When it expires, browsers immediately stop trusting the site and throw a full-page warning — "Your connection is not private" — that blocks visitors cold. Nothing is permanently broken, but your site is effectively down until you renew. For the full picture, see what happens when an SSL certificate expires, and if it's already expired, here's how to fix it fast.
Auto-renewal isn't a guarantee
Most certificates are set to renew automatically — but automated renewal fails silently more often than anyone expects: a broken cron job, an expired API token, a DNS change, or a domain that itself lapsed. The renewal system going quiet is exactly when you most need an independent warning. Checking once with this tool is useful; being told before the date arrives is what actually prevents downtime.
That's what DomainChest does: add a domain once and it watches the live certificate — and the domain registration alongside it — then emails you well before either expires.
Frequently asked questions
How does this SSL checker work?
It opens a live TLS connection to the domain on port 443 — exactly like a browser does — and reads the certificate the server presents, including its expiration date. No login or agent is needed because the certificate is public.
Is it free?
Yes, checking any site's certificate is completely free and needs no account. If you'd like an email before a certificate expires, you can monitor it with a free DomainChest account (up to three domains).
What happens when an SSL certificate expires?
Browsers stop trusting the site and show a full-page security warning like 'Your connection is not private,' which blocks visitors until it's renewed. It doesn't damage anything permanently, but it scares away traffic and breaks API calls until fixed.
How long are SSL certificates valid?
It varies. Let's Encrypt certificates last 90 days and are meant to auto-renew; many paid certificates last a year. Shorter lifetimes mean more renewals — and more chances for an automated renewal to fail silently.
Why should I monitor certificate expiry separately from auto-renewal?
Because auto-renewal fails quietly more often than people expect — a broken cron job, an expired API token, or a DNS change can stop it without any error you'd notice. An independent monitor catches that and warns you before visitors ever see a warning.
Related tool: Domain & SSL Expiry Checker— check a domain's registration expiry and registrar too.
Never serve an expired certificate again
Store your domains in a chest, so you never forget one again.
Start free — 3 domains