---
title: "SSL Certificate Checker"
description: "Check any website's SSL certificate — expiration date, chain validity, hostname match, key size, and TLS version. No signup; a scan usually finishes within a minute."
url: https://findutils.com/network/ssl-certificate-checker/
category: network
---

# SSL Certificate Checker

Check any website's SSL certificate — expiration date, chain validity, hostname match, key size, and TLS version. No signup; a scan usually finishes within a minute.

**Use this tool:** [SSL Certificate Checker](https://findutils.com/network/ssl-certificate-checker/)

## Programmatic access

- REST id `ssl-certificate-checker`: POST https://api.findutils.com/api/tools/ssl-certificate-checker/execute (reference: https://findutils.com/api/ssl-certificate-checker/)
- MCP tool `ssl_certificate_checker` on https://mcp.findutils.com (reference: https://findutils.com/mcp/ssl-certificate-checker/)

## Why Check SSL Certificates?

SSL certificates encrypt data between browsers and servers. An expired or misconfigured certificate can expose users to security risks and cause browser warnings that damage trust.

## SSL Certificate Best Practices & Error Fixes

- Set a calendar reminder 30 days before expiration. Use automatic renewal via Let's Encrypt certbot or your hosting provider's ACME client to avoid manual renewal risk entirely.
- Seeing NET::ERR_CERT_DATE_INVALID? The certificate has expired or the visitor's system clock is off. Check the Valid To date shown above and renew if needed.
- Seeing ERR_CERT_AUTHORITY_INVALID? The intermediate CA is probably missing. Concatenate the leaf certificate + intermediate bundle into one file (Let's Encrypt provides fullchain.pem) and point your server at that file.
- Seeing ERR_CERT_COMMON_NAME_INVALID? The hostname isn't in the certificate's SAN list. Reissue the certificate and include every hostname (apex + subdomains) you serve.
- Use 2048-bit RSA or 256-bit ECC as the minimum key size. ECC is smaller, faster in TLS handshakes, and recommended for new certificates.
- After renewal, verify the full chain with this checker before closing the maintenance window — a working-but-broken chain will fail for some mobile browsers and API clients even when your browser shows green.

## Frequently Asked Questions

### How do I check if my SSL certificate is about to expire?

Enter your domain above and press Check Certificate. The tool shows the exact expiration date and a color-coded 'Days Remaining' badge — green if you have more than 30 days, amber at 30 days or fewer, and red if it has expired. Set a calendar reminder 30 days before the date shown.

### What does 'NET::ERR_CERT_DATE_INVALID' mean?

Chrome shows this error when the certificate has expired, hasn't started being valid yet (clock skew), or the visitor's system clock is wrong. Run this tool to see the actual valid-from and valid-to dates on the certificate. If they look correct, ask the visitor to check their device's date and time settings.

### How do I fix 'ERR_CERT_AUTHORITY_INVALID'?

The browser doesn't trust the certificate's issuer. Causes include: using a self-signed certificate, a missing intermediate CA in the server's bundle, or a CA that isn't in the browser's trust store. Check the Issuer field in the result — if it shows a known CA (Let's Encrypt, DigiCert, etc.), the fix is usually adding the CA's intermediate bundle to your server configuration.

### What causes 'ERR_CERT_COMMON_NAME_INVALID'?

The certificate doesn't cover the hostname the visitor typed. For example, a certificate issued for example.com will not work for www.example.com unless www.example.com is listed as a Subject Alternative Name. Check the SAN list in the result. Fix by reissuing the certificate with every hostname you serve.

### What happens if a certificate expires?

Browsers block the page with a full-screen security warning and most users back out. Search rankings can drop because Google crawls won't reach cached pages, bounce rate spikes, and any API or service depending on HTTPS to your domain fails. Renew at least 7 days before expiration to be safe.

### What is certificate chain validation and how do I fix a broken chain?

A chain links your site's certificate to a trusted root CA via one or more intermediate certificates. If the intermediate is missing, Firefox and Safari may work but Chrome and many mobile browsers will fail. Fix by concatenating the full chain (leaf + intermediate(s)) into your server's certificate file — Let's Encrypt provides this as fullchain.pem.

### Is this SSL checker unlimited?

Yes. No signup, no daily scan limits. Enter any publicly-accessible domain and get results. No account required.

### What key size should my SSL certificate use?

At least 2048-bit RSA or 256-bit ECC (ECDSA). Shorter keys are rejected by modern browsers and CAs. 4096-bit RSA works but handshakes are slower; 256-bit ECC is smaller and faster and generally preferred for new certificates.

### What's the difference between SSL and TLS?

TLS (Transport Layer Security) is the successor to SSL (Secure Sockets Layer). All modern HTTPS uses TLS 1.2 or TLS 1.3 — SSL 2.0 and 3.0 are long deprecated. 'SSL certificate' is still the common name for what is technically a TLS certificate. This tool works with any TLS version.

### Does HTTPS affect SEO rankings?

Yes. Google confirmed HTTPS as a ranking signal, and Chrome marks HTTP pages as Not Secure, which hurts bounce rate. A valid SSL certificate is table-stakes for ranking. Pair this checker with the security-headers-analyzer to cover the full HTTPS configuration.

### What are Subject Alternative Names (SANs)?

SANs are additional hostnames covered by a single certificate. A certificate for example.com might also list www.example.com, api.example.com, and mail.example.com as SANs. If a visitor hits a hostname not on the list, the browser shows ERR_CERT_COMMON_NAME_INVALID.

### Can I check SSL certificates for internal or staging domains?

Only publicly-accessible domains. Internal domains that aren't reachable from the public internet can't be reached by the FindUtils scan service, so they can't be checked here. For those, use openssl s_client -connect internal.example:443 -showcerts on your local network.

### What leaves my device when I use this tool?

The domain name you enter. The page sends it to the FindUtils scan service at app.findutils.com, which opens a TLS connection to that domain, reads the certificate chain, and returns the result to your browser. A scan usually finishes within a minute and can take up to two. The service keeps standard request logs, described in the privacy policy.

## Related Tools

- [Security Headers Analyzer](https://findutils.com/network/security-headers-analyzer/)
- [URL Safety Checker](https://findutils.com/security/url-safety-checker/)
- [DNS Security Scanner](https://findutils.com/network/dns-security-scanner/)
- [DNS Lookup](https://findutils.com/network/dns-lookup/)
- [Email Security Checker](https://findutils.com/security/email-security-checker/)
- [Email Validator](https://findutils.com/security/email-validator/)
- [IP Address Lookup](https://findutils.com/network/ip-address-lookup/)
- [Cookie Analyzer](https://findutils.com/security/cookie-analyzer/)
