Days until expiry
The exact expiry date and how many days remain — the number one cause of preventable SSL-related outages.
Enter a domain to instantly check its SSL/TLS certificate: days until expiry, issuer, valid dates, TLS protocol, and whether the chain is trusted.
Start your 7-day trial — no credit card, free plan after.
Enter a domain (for example, northduty.com). NorthDuty connects over HTTPS and reports the live certificate details.
Free check. No signup. Results are not published or indexed.
Enter a domain (for example, northduty.com). NorthDuty connects over HTTPS and reports the live certificate details. Recurring checks are configured inside the NorthDuty app.
A single check returns the certificate facts that most often cause outages and browser warnings.
The exact expiry date and how many days remain — the number one cause of preventable SSL-related outages.
Which certificate authority issued the certificate and which hostnames it covers, so you can confirm it matches the domain.
The certificate's full validity window, including not-before dates that can break a freshly rotated certificate.
The negotiated TLS protocol version and whether the presented chain is trusted by standard root stores.
Expired or misconfigured certificates take sites offline in a way uptime pings often miss until customers complain.
No signup, no agent — just a live HTTPS connection to the domain you enter.
Type any public domain or hostname. NorthDuty resolves it and opens an HTTPS connection on port 443.
The presented certificate is parsed for issuer, subject, validity dates, and the negotiated TLS protocol.
Days-to-expiry, trust status, and the key dates are shown immediately — no report snapshot is stored.
Add the domain to NorthDuty and get alerted automatically before the certificate expires, on every renewal.
What each browser warning means, and what causes it. A certificate can be perfectly valid and still produce every one of these.
| What the browser says | What is wrong | Usual cause |
|---|---|---|
| Certificate has expired | Valid-to date has passed | Auto-renewal silently stopped, or a renewal that was never installed on the server |
| Certificate is not valid for this name | The name being visited is not covered | www missing from the certificate, or a new subdomain added without reissuing — the apex works, so nobody notices |
| Issuer not trusted / incomplete chain | An intermediate certificate is missing | Only the leaf was installed; Chrome often fetches the missing link and hides the problem, stricter clients and apps do not |
| Not yet valid | The valid-from date is in the future | A freshly issued certificate installed early, or a server clock that is wrong |
| Mixed content warning | Page is HTTPS but loads HTTP assets | A hard-coded http:// URL in a theme, plugin or ad tag |
Automation moves the failure rather than removing it.
The new certificate is issued and written to disk, but nginx or Apache is never reloaded, so the old one is still being served until the next restart.
A redirect rule, a firewall or a CDN starts blocking the /.well-known/acme-challenge path, and renewals fail quietly from then on.
The edge has a valid certificate while the origin's has expired. Anything connecting directly to the origin fails.
A 90-day certificate renews around day 60. If renewals have been failing for a month, you have weeks of warning — and only if something is watching.
A campaign subdomain or a www variant added without reissuing. The certificate is valid; it just does not cover that name.
Expiry notices go to whichever address registered the certificate, often a developer who has since left.
Use the tool preview for a quick answer, then move into recurring monitoring for your most important pages and journeys.
Feature
Monitor SSL certificates with NorthDuty website health checks so validity, trust, and expiry issues are visible before visitors are blocked.
Explore SSL Certificate MonitoringFeature
Monitor uptime every 5 minutes by default with HTTP, SSL, DNS, blank-page detection, broken resources, JavaScript errors, and API call tracking.
Explore Uptime MonitoringPricing
NorthDuty plans are sized by how many checkout, signup and login journeys you monitor: Free, $29 Starter, $79 Pro, $199 Business. 7-day trial, no card.
Compare pricing plansAnswers about this diagnostic preview and when to move into recurring monitoring.
Enter the domain above: the checker connects over HTTPS and reports the exact valid-to date, days remaining, issuer, the hostnames the certificate covers, the negotiated TLS version and whether the chain is trusted.
The certificate does not cover the www hostname. It is a common and long-lived defect because the bare domain works, so most people and most monitoring never see it — only visitors arriving at www do.
Yes. Renewal failures are quiet: a web server that was never reloaded, a blocked validation path, or an origin certificate left behind when traffic moved to a CDN. Automation fails as silently as it succeeds.
The server sends its own certificate but not the intermediate that links it to a trusted root. Desktop Chrome often fetches the missing intermediate itself and shows no error, while stricter clients — mobile apps, API consumers, payment integrations — refuse the connection.
Yes. The SSL certificate checker is completely free and requires no signup. Enter a domain and you get the live certificate details immediately.
It opens a standard HTTPS (TLS) connection to the domain you enter on port 443 and reads the certificate the server presents — the same certificate a browser would receive.
NorthDuty does not create a stored or indexed public report. If you copy a share link, the domain remains in that URL and opening it reruns a live check.
This tool answers a single point-in-time question. NorthDuty checks SSL continuously as part of every website health check and alerts you in advance of expiry, so a missed renewal never becomes an outage.
A one-off SSL check is useful, but certificates expire on a schedule. Let NorthDuty watch your certificates continuously and alert you before they lapse.
7 days with Pro features and limits, no credit card — then keep one daily journey on the free plan.