SSL certificate check: what your server is really serving

An SSL certificate check shows what your server actually serves over HTTPS right now: the certificate, who issued it, how many days are left, whether the name matches your domain, whether the chain is trusted, which TLS versions and ciphers are enabled, and whether HSTS is on. It reads your public endpoint only — we do not issue, renew or install certificates.

The certificate your server hands out, in plain language, and what is worth fixing first.

Free. 54 checks, five on TLS and HTTPS. No signup.

What you get after the check

Type a domain and the free report opens — 54 checks, five of them TLS and HTTPS. In that group: the issuer and validity dates, the days left, whether the name inside the certificate matches your domain, whether the chain is complete, which TLS versions and ciphers the server accepts, whether HSTS is present, and what the plain http:// address returns — a permanent redirect, a temporary one, or the page itself. No account, no access to your server, no private key; requests are rate-limited per IP.

How to read the result: six certificate states

The next step differs in every case: these are the six states, with the names the report uses.

What you seeWhat it meansWhat to do
Certificate is validA trusted authority signed it, the name matches, the chain is complete.Read the two sections below.
Expiring soonFewer than 30 days left; under 14 the report raises the severity.Renew it, then re-check.
ExpiredBrowsers stop every visitor with a “connection is not secure” warning.Renew and re-check; the warning cannot be talked away.
Name mismatchThe certificate is genuine, but the name inside it is not the one requested — often it covers example.com but not www.example.com.Get a certificate listing every name you serve.
Chain not trustedThe certificate is fine, but the server does not send the intermediate certificate that links it to a trusted root.Install the full chain, not just the certificate.
Weak or outdatedAn old SHA-1 signature, a short RSA key, or outdated protocols left on — findings with severity, not “invalid”.Move to SHA-256 and a 2048-bit key.

“The certificate is valid — so why does the browser still say Not secure?”

A certificate says the connection is encrypted and the domain name matches. It says nothing about what else the page loads. That is why an SSL certificate checker can show a clean certificate while the browser warns. Four things cause it, and all four are in the free report. Those causes sit in TLS and HTTPS; a “Not secure” mark can also come from what the page loads, its headers or its content, which the same free perimeter check covers.

Run the perimeter check

What we check in TLS and HTTPS

Five checks cover this group, and the report uses these exact names.

What a certificate check cannot prove

A certificate is easy to over-read. Here is the honest shape of it: what your server serves right now, what it means, and what the check does not cover.

A check tells you what is being served right now — nothing more.

Certificate lifetimes are getting shorter

Ballot SC-081v3 (April 2025; votes from Apple, Google, Microsoft and Mozilla) cuts the maximum validity of a publicly trusted TLS certificate from 398 to 200 days from 15 March 2026, to 100 days from 15 March 2027 and 47 days from 15 March 2029 (Baseline Requirements §6.3.2; as of October 2026). The consequence: renewal that depends on someone remembering now comes round several times more often, and a missed renewal puts the warning in front of every visitor at once.

How to check a certificate yourself

In the browser: click the padlock, then “Connection is secure”, then “Certificate is valid”. That panel shows the issuer, the validity dates and the names the certificate covers — compare them with your domain.

From a terminal, one command prints the same essentials:

openssl s_client -connect yourdomain.com:443 -servername yourdomain.com | openssl x509 -noout -subject -issuer -dates

Subject is the name the certificate was issued for, Issuer is the authority that signed it, and notBefore and notAfter are the validity window — those two lines are the quickest way to check SSL certificate expiry yourself. Point the command at your own domain, or at public data for a domain you are responsible for: certificates and handshakes are public by nature. The terminal shows what the certificate contains, not what a browser sees on the live page — mixed content, a missing redirect from http://, HSTS — and that takes a request to the page, which is what the check above does.

What else the scan looks at

TLS and HTTPS is 5 of the 54 checks in the free scan. The rest cover response headers and cookies, exposed files and backups, third-party code, login panels, reputation and registration data, subdomains, and email and DNS records.

We read your external perimeter from public data: this is not a pentest and not an audit of the server from inside — nothing is exploited, nothing is changed.

Run the full 54-check scanHow the checks work

BlindspotScan team

We read what your public endpoint serves. We do not log in anywhere, we do not use private keys, and we do not exploit anything we find. Checks are rate-limited per IP.

How the checks workContact us

FAQ

What does an SSL certificate check show?

It shows what the server serves for HTTPS — the certificate and its issuer, the validity dates and days left, whether the name and the chain check out, which TLS versions and ciphers are accepted, whether HSTS is on, and what the plain http:// address does. None of that needs your private key or access to the server.

How do I check my SSL certificate?

The check on this page is the fastest route: type your domain and the TLS check opens with the certificate, the days left and the protocols. To look yourself, click the padlock in your browser, or run openssl s_client -connect yourdomain.com:443 -servername yourdomain.com in a terminal.

My certificate looks valid but the browser says “Not secure” — why?

Mixed content is the usual cause: the page loads over HTTPS, but some images, scripts, stylesheets or iframes are requested over plain http://, so the browser marks the page as not fully secure and blocks active mixed content outright. The same warning also appears when a plain http:// version of the page still opens without a redirect, when HSTS is missing, or when old protocols and ciphers are left on. None of those are faults in the certificate.

How long is left before my certificate expires, and what happens if it does?

The free report shows the expiry date, counts the days left and raises the severity under 30 days and again under 14. We do not renew anything: the next certificate comes from your hosting provider, your control panel or an ACME client. If a renewal never reaches the live server, every visitor meets a full-page browser warning and many turn back. Nothing is broken into and nothing is stolen: the connection simply cannot be confirmed as yours.

What is a certificate chain, and what does “not trusted” mean?

A certificate chain runs from your domain's certificate through an intermediate certificate to a root certificate that browsers already trust. “Not trusted” usually means the server does not send that intermediate certificate — or sends the chain in the wrong order — so the browser cannot reach the root. The report flags the chain, not the certificate; the fix is to install the full chain rather than the certificate alone.

Can I check a certificate for a domain I don't own?

Yes. A certificate and the TLS handshake are public data — every client that connects receives the same certificate, which is what makes a certificate check possible. Our check stays passive: one ordinary connection reading what the server already publishes, rate-limited per IP.

Does HTTPS make my site secure?

No. HTTPS protects the connection between a visitor and your site: it is encrypted, and the certificate confirms the domain. It says nothing about the site itself — an exposed .env file, an outdated CMS, an open login panel or missing security headers all stay as they were, and the same free scan covers them.

Run the full 54-check scanHow the checks workWhat the deep scan adds