Free SSL Certificate Checker

Enter a domain to instantly check its SSL/TLS certificate: days until expiry, issuer, valid dates, TLS protocol, and whether the chain is trusted.

Start your 7-day trial — no credit card, free plan after.

Check an SSL certificate

Enter a domain (for example, northduty.com). NorthDuty connects over HTTPS and reports the live certificate details.

Free check. No signup. Results are not published or indexed.

How NorthDuty SSL monitoring works

Enter a domain (for example, northduty.com). NorthDuty connects over HTTPS and reports the live certificate details. Recurring checks are configured inside the NorthDuty app.

What this SSL checker reports

A single check returns the certificate facts that most often cause outages and browser warnings.

Days until expiry

The exact expiry date and how many days remain — the number one cause of preventable SSL-related outages.

Issuer and subject

Which certificate authority issued the certificate and which hostnames it covers, so you can confirm it matches the domain.

Valid-from and valid-to dates

The certificate's full validity window, including not-before dates that can break a freshly rotated certificate.

TLS protocol and trust

The negotiated TLS protocol version and whether the presented chain is trusted by standard root stores.

Why check SSL certificates

Expired or misconfigured certificates take sites offline in a way uptime pings often miss until customers complain.

How the SSL checker works

No signup, no agent — just a live HTTPS connection to the domain you enter.

1

Enter a domain

Type any public domain or hostname. NorthDuty resolves it and opens an HTTPS connection on port 443.

2

We read the live certificate

The presented certificate is parsed for issuer, subject, validity dates, and the negotiated TLS protocol.

3

You get a plain-language result

Days-to-expiry, trust status, and the key dates are shown immediately — no report snapshot is stored.

4

Turn it into continuous monitoring

Add the domain to NorthDuty and get alerted automatically before the certificate expires, on every renewal.

The SSL errors visitors actually hit

What each browser warning means, and what causes it. A certificate can be perfectly valid and still produce every one of these.

What the browser saysWhat is wrongUsual cause
Certificate has expiredValid-to date has passedAuto-renewal silently stopped, or a renewal that was never installed on the server
Certificate is not valid for this nameThe name being visited is not coveredwww missing from the certificate, or a new subdomain added without reissuing — the apex works, so nobody notices
Issuer not trusted / incomplete chainAn intermediate certificate is missingOnly the leaf was installed; Chrome often fetches the missing link and hides the problem, stricter clients and apps do not
Not yet validThe valid-from date is in the futureA freshly issued certificate installed early, or a server clock that is wrong
Mixed content warningPage is HTTPS but loads HTTP assetsA hard-coded http:// URL in a theme, plugin or ad tag

Why certificates lapse even with auto-renewal

Automation moves the failure rather than removing it.

Renewal succeeds, reload does not

The new certificate is issued and written to disk, but nginx or Apache is never reloaded, so the old one is still being served until the next restart.

The validation path broke

A redirect rule, a firewall or a CDN starts blocking the /.well-known/acme-challenge path, and renewals fail quietly from then on.

The certificate moved to the CDN

The edge has a valid certificate while the origin's has expired. Anything connecting directly to the origin fails.

Short lifetimes cut the margin

A 90-day certificate renews around day 60. If renewals have been failing for a month, you have weeks of warning — and only if something is watching.

A new hostname was added

A campaign subdomain or a www variant added without reissuing. The certificate is valid; it just does not cover that name.

Nobody owns the alert

Expiry notices go to whichever address registered the certificate, often a developer who has since left.

Go Beyond One-Off Checks

Use the tool preview for a quick answer, then move into recurring monitoring for your most important pages and journeys.

Frequently Asked Questions

Answers about this diagnostic preview and when to move into recurring monitoring.

How do I check when an SSL certificate expires?

Enter the domain above: the checker connects over HTTPS and reports the exact valid-to date, days remaining, issuer, the hostnames the certificate covers, the negotiated TLS version and whether the chain is trusted.

Why does my site show a certificate error on www but not without it?

The certificate does not cover the www hostname. It is a common and long-lived defect because the bare domain works, so most people and most monitoring never see it — only visitors arriving at www do.

My certificate renews automatically. Do I still need to check it?

Yes. Renewal failures are quiet: a web server that was never reloaded, a blocked validation path, or an origin certificate left behind when traffic moved to a CDN. Automation fails as silently as it succeeds.

What is an incomplete certificate chain?

The server sends its own certificate but not the intermediate that links it to a trusted root. Desktop Chrome often fetches the missing intermediate itself and shows no error, while stricter clients — mobile apps, API consumers, payment integrations — refuse the connection.

Is this SSL checker free?

Yes. The SSL certificate checker is completely free and requires no signup. Enter a domain and you get the live certificate details immediately.

What does the checker actually connect to?

It opens a standard HTTPS (TLS) connection to the domain you enter on port 443 and reads the certificate the server presents — the same certificate a browser would receive.

Do you store the domains I check?

NorthDuty does not create a stored or indexed public report. If you copy a share link, the domain remains in that URL and opening it reruns a live check.

How is this different from monitoring SSL with NorthDuty?

This tool answers a single point-in-time question. NorthDuty checks SSL continuously as part of every website health check and alerts you in advance of expiry, so a missed renewal never becomes an outage.

Start monitoring your website with NorthDuty today.

A one-off SSL check is useful, but certificates expire on a schedule. Let NorthDuty watch your certificates continuously and alert you before they lapse.

7 days with Pro features and limits, no credit card — then keep one daily journey on the free plan.