Check an SSL Certificate

Check whether a website or mail server has a valid SSL certificate. See the expiration date, issuer and certificate details.

Examples: theory7.net google.com github.com wikipedia.org

Checking SSL certificate...

Why SSL matters

An SSL certificate (Secure Sockets Layer) is essential for every website today. SSL creates an encrypted connection between a visitor's web browser and your web server, so sensitive information such as passwords, credit card details and personal data stays safe while it travels across the internet.

Google has used SSL as a ranking factor since 2014, which means websites without an SSL certificate rank lower in search results. Modern browsers such as Chrome and Firefox flag websites without SSL with a clear "Not secure" warning, which scares visitors away and hurts your conversion rate. Research shows that 84% of users abandon a purchase when they notice a website is not secure.

For online stores and websites that process payments, SSL is not only required for PCI DSS compliance, it is also essential for customer trust. SSL also makes your website faster when you use HTTP/2, which only works over secure HTTPS connections.

What does this SSL check tool check?

Our free SSL check tool fetches the SSL certificate that a website or mail server presents and checks its key details:

  • Certificate validity: checks whether the SSL certificate is still valid and has not expired
  • Domain name verification: verifies whether the certificate was issued for the right domain name (Common Name and Subject Alternative Names)
  • Certificate chain: shows how many certificates the server sends in the certificate chain
  • Certificate Authority (CA): identifies which certificate authority issued the certificate
  • Expiration date: shows when the certificate expires and whether it needs to be renewed
  • Certificate type: recognizes well-known issuers such as Let's Encrypt, Sectigo, DigiCert and GlobalSign
  • Subject Alternative Names: lists every domain name the certificate is valid for
  • Mail servers: also checks the certificate of IMAP and SMTP servers, over direct TLS or via STARTTLS
  • Self-signed warnings: whether it is a self-signed certificate

Types of SSL certificates

There are several types of SSL certificates, each with a different validation level:

Type Validation level Suitable for Cost
Domain Validation (DV) Basic: domain check only Blogs, portfolio sites, small websites €0 - €50/year
Organization Validation (OV) Medium: business verification Business websites, professional services €50 - €200/year
Extended Validation (EV) Highest: extensive verification Online stores, banks, large e-commerce €150 - €500/year
Let's Encrypt Basic: automated DV All websites, ideal for beginners Free
Wildcard SSL Basic or higher: for subdomains Websites with multiple subdomains €80 - €300/year

Domain Validation (DV) certificates are the most common type. The CA only checks whether you own the domain, usually through email verification or a DNS record. This process takes a few minutes and is fully automated.

Organization Validation (OV) certificates require the CA to verify your business details through official registers such as the Chamber of Commerce. This process takes 1-3 business days.

Extended Validation (EV) certificates offer the highest validation level, with an extensive review of your organization. EV remains valuable for organizations that want to convey maximum trust.

Renewing an SSL certificate

SSL certificates are valid for a limited time, usually 90 days (Let's Encrypt) or 1-2 years (commercial certificates). Renewing your certificate on time is crucial. When an SSL certificate expires, visitors get a security warning that will scare most of them away.

Use our SSL check tool to regularly check when your certificate expires. With Let's Encrypt, renewal is fully automatic through the certbot software. The ACME protocol makes sure your certificate is renewed every 60 days without any manual steps.

Commercial certificates usually have to be renewed manually: generate a CSR, pay and install the new certificate.

SSL and SEO

In 2014 Google announced that HTTPS is a ranking factor. Websites with SSL get an SEO boost compared to unsecured HTTP sites. SSL is also a requirement for HTTP/2 and HTTP/3, which offer much faster load times.

Websites without SSL have a higher bounce rate because of the "Not secure" warning. Make sure every page has a 301 redirect from HTTP to HTTPS, update your sitemap.xml with HTTPS URLs, and set up canonical tags with HTTPS. Use our SEO check tool to verify that your website is configured correctly.

How does SSL/TLS work?

SSL (Secure Sockets Layer) is the predecessor of TLS (Transport Layer Security). Modern websites use TLS 1.2 or TLS 1.3, because older versions are no longer secure.

When a visitor opens your HTTPS website, a TLS handshake takes place:

  1. Client Hello: the browser sends its supported TLS versions, cipher suites and a random number to the server
  2. Server Hello: the server picks the best TLS version and cipher suite and sends back its SSL certificate
  3. Certificate verification: the browser checks the validity, the expiration date and whether the CA is trusted
  4. Key exchange: the browser and server exchange cryptographic keys using RSA or Diffie-Hellman
  5. Secure connection: all further communication is encrypted symmetrically (usually AES-256)

The certificate chain of trust is essential: your certificate is issued by a CA that has a root certificate trusted by default in all browsers. Our SSL check shows how many certificates the server sends in the chain, so a missing intermediate certificate stands out. For technical insights you can also use our HTTP headers tool.

TLS 1.3 optimized the handshake process with one round trip fewer than TLS 1.2 and only supports strong cryptographic algorithms.

Installing an SSL certificate

Installing an SSL certificate differs per platform:

cPanel hosting
With cPanel hosting, installing SSL is easy: go to "SSL/TLS Status" or "Let's Encrypt SSL", select your domain and click "Install". Let's Encrypt is fully automatic.

Apache web server
Upload the certificate files to /etc/ssl/certs/ and configure the VirtualHost:

<VirtualHost *:443>
    ServerName www.your-domain.com
    SSLEngine on
    SSLCertificateFile /etc/ssl/certs/your-domain.crt
    SSLCertificateKeyFile /etc/ssl/private/your-domain.key
    SSLCertificateChainFile /etc/ssl/certs/intermediate.crt
</VirtualHost>

Nginx web server
Combine the certificate and intermediate into one file and configure the server block:

server {
    listen 443 ssl http2;
    server_name www.your-domain.com;
    ssl_certificate /etc/ssl/certs/your-domain-fullchain.crt;
    ssl_certificate_key /etc/ssl/private/your-domain.key;
    ssl_protocols TLSv1.2 TLSv1.3;
}

After installation, use our SSL check to verify that everything works correctly.

Common SSL errors

Even with a valid SSL certificate, configuration mistakes can lead to warnings:

ERR_CERT_DATE_INVALID: the certificate has expired. Solution: renew it right away and use our SSL check to check the expiration date.

ERR_CERT_COMMON_NAME_INVALID: the domain does not match the domain names in the certificate. Solution: use a certificate with a SAN that covers both variants (with and without www).

NET::ERR_CERT_AUTHORITY_INVALID: the certificate chain is incomplete or the CA is not trusted. Solution: install the full chain with intermediate certificates.

Mixed content warnings: an HTTPS page loads resources over HTTP. Solution: update all links to HTTPS or use a CSP header with upgrade-insecure-requests.

SSL certificate chain incomplete: intermediate certificates are missing. Solution: install the ca-bundle.crt file together with your domain certificate.

Free SSL with Let's Encrypt

Let's Encrypt transformed the SSL world by offering free, automated SSL certificates. Let's Encrypt certificates are Domain Validation (DV) certificates with a validity of 90 days. The short validity period encourages automatic renewal.

How does Let's Encrypt work?
The ACME protocol (Automatic Certificate Management Environment) issues certificates without human intervention through challenges:

  • HTTP-01 challenge: certbot places a file in /.well-known/acme-challenge/
  • DNS-01 challenge: certbot adds a TXT record to DNS, which is required for wildcard certificates

A cron job makes sure the certificate is renewed every 60 days. With Theory7 web hosting, Let's Encrypt is integrated by default through AutoSSL.

Wildcard SSL certificates

A wildcard SSL certificate secures your main domain plus all first-level subdomains with a single certificate. For example: *.example.com secures www.example.com, shop.example.com, blog.example.com, and so on.

Wildcard certificates are ideal for:

  • Multi-tenant SaaS applications with customer subdomains
  • Large websites with many subdomains that change often
  • Development/staging environments with multiple test subdomains

Let's Encrypt supports free wildcard certificates through the DNS-01 challenge. Your DNS provider must support API access for automatic renewal.

SSL for online stores and e-commerce

For online stores SSL is mandatory. Payment providers such as Stripe, Mollie and PayPal require HTTPS for checkout pages. PCI DSS compliance requires that:

  • All payment pages use TLS 1.2 or higher
  • Outdated SSL protocols are completely disabled
  • Weak cipher suites (DES, RC4, MD5) are not supported
  • Keys are at least 2048-bit RSA or 256-bit ECC
  • Mixed content is avoided completely

This SSL check does not test PCI DSS requirements: the tool checks the certificate itself (validity, domain name and issuer). To test TLS versions and cipher suites, use an external scanner such as SSL Labs.

Best practices for online store SSL:

  • Force HTTPS on all pages with an HSTS header
  • Implement a Content-Security-Policy that blocks mixed content
  • Update all tracking scripts to their HTTPS versions
  • Use our WHOIS lookup tool to verify the domain registration

Checking an SSL certificate: step by step

How do you use our free SSL check tool?

  1. Enter your domain: type your domain name in the input field at the top of this page
  2. Click "Check": the tool fetches the certificate and checks it right away
  3. Check the status: green check mark = valid, red warning = problems
  4. Review the details: issuer, validity, days remaining, domain match and the number of certificates in the chain
  5. Fix any problems: use the advice in this article
  6. Test again: run the SSL check again after making changes

For the complete picture, combine this SSL check with:

Run this SSL check at least once a month for optimal security.

SSL best practices in a nutshell

For an optimally secured website with SSL, follow these recommendations:

  • Use at least TLS 1.2 and disable SSLv3 and TLS 1.0/1.1
  • Choose strong cipher suites with forward secrecy (ECDHE)
  • Use keys of at least RSA 2048-bit (or 4096-bit for very sensitive data)
  • Install the full certificate chain including intermediate certificates
  • Force HTTPS with 301 redirects and an HSTS header
  • Avoid mixed content by loading all resources over HTTPS
  • Renew certificates at least 30 days before they expire
  • Use OCSP stapling for faster certificate validation
  • Implement CAA DNS records to specify which CAs may issue certificates for your domain
  • Test regularly with our SSL check tool and external services such as SSL Labs

With a correctly configured SSL certificate you not only protect your visitors' data, you also improve your SEO rankings, increase customer trust and meet modern web standards. At Theory7 you get free Let's Encrypt SSL with automatic renewal as standard on all our hosting plans, so your website is always optimally secured. Combine this SSL check with our DNS Lookup to check whether your CAA records are set up correctly.

Frequently asked questions

What is an SSL certificate?

An SSL certificate (officially TLS these days) is a digital certificate that encrypts the connection between a web browser and a website. It makes sure that sensitive information such as passwords, credit card details and personal data is transferred securely. You can recognize websites with SSL by the padlock in the address bar and the https:// prefix.

How do I know if a website has SSL?

You can recognize a website with SSL by the padlock icon in your browser's address bar and a URL that starts with 'https://' instead of 'http://'. With our SSL check tool you can look up detailed information about the certificate, such as the issuer, validity and expiration date.

What is the difference between DV, OV and EV certificates?

There are three types of SSL certificates: DV (Domain Validation) only validates ownership of the domain, OV (Organization Validation) also validates the organization behind the domain, and EV (Extended Validation) goes furthest with an extensive verification of the organization. Since 2019 the major browsers no longer show the company name of an EV certificate in the address bar; the EV details are visible in the certificate information. For most websites a DV certificate is enough.

What happens when an SSL certificate expires?

When an SSL certificate expires, modern browsers show a warning that the connection is not secure. Visitors see an error message and cannot continue to the website without ignoring this warning. This hurts trust and your SEO ranking. That is why it is important to renew certificates on time, preferably at least 30 days before the expiration date.

Is a free SSL certificate (Let's Encrypt) secure enough?

Yes, free SSL certificates from Let's Encrypt offer the same encryption and security as paid certificates. They are fully trusted by all modern browsers and are used by millions of websites worldwide. The main difference is that Let's Encrypt certificates are valid for 90 days (paid certificates often for 1 year) and only offer DV validation. For most websites this is more than enough.