VMHeaven

Free tool

SSL certificate checker

Check a site's SSL/TLS certificate: expiry date, hostname match, the chain and missing intermediates, key size, TLS 1.3 and 1.2 support and OCSP stapling.

Check a certificate

Try:

A TLS handshake from our test server in Amsterdam to port 443 — no page is requested. Redirects, headers and response times are on the HTTP header checker.

What the check looks at

CheckWhat a browser does when it fails
ExpiryShows a full-page warning; most users leave
Name matchWarns that the certificate belongs to another site — often a missing www or subdomain
ChainDesktop browsers may cope from their cache; apps, curl and older phones refuse the connection
Key and signatureRefuses SHA-1 signatures; keys under 2048-bit RSA are no longer issued
TLS versionRefuses TLS 1.0 and 1.1

Fixing the common problems

Incomplete chain. Point the server at the full chain. With certbot that is fullchain.pem:

nginx
ssl_certificate     /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols       TLSv1.2 TLSv1.3;

Name mismatch. Request the certificate for every name the site answers on, including www: certbot --nginx -d example.com -d www.example.com.

Expiring. Find out why renewal stopped before it runs out:

Linux
certbot renew --dry-run
systemctl list-timers | grep certbot

Check it from a terminal

Linux · macOS
# the chain the server sends
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null

# dates, subject and issuer of the site's certificate
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
  | openssl x509 -noout -dates -subject -issuer

Behind Cloudflare or another CDN, the certificate a visitor sees is the CDN’s; the one on your own server only matters between the CDN and the server, which is where errors such as 525 and 526 come from. To see that one, run the openssl s_client command above against your server’s own address, with -servername set to your domain.

Frequently asked

What does an incomplete chain mean?

The server sends its own certificate but not the intermediate certificate that links it to a root the client trusts. Desktop browsers often fill the gap from their cache, so the site looks fine in yours, while curl, apps, payment callbacks and older phones fail. Configure the server with the full chain — with Let's Encrypt and certbot that is fullchain.pem, not cert.pem.

When does a certificate need renewing?

Before the date shown as Expires. Let's Encrypt certificates are valid for 90 days and certbot renews them once fewer than 30 days are left, so a Let's Encrypt certificate with under three weeks to go usually means automatic renewal is failing — certbot renew --dry-run shows why. The industry is moving to shorter lifetimes, so renewal has to be automatic either way.

Is OCSP stapling required?

No. Stapling lets the server hand over proof that its certificate has not been revoked, but browsers do not require it, and Let's Encrypt stopped running OCSP in 2025, so its certificates have nothing to staple. The check reports it as a note, not as a problem.

Which TLS versions should a server offer?

TLS 1.3 and TLS 1.2. TLS 1.0 and 1.1 are refused by current browsers and should be switched off. TLS 1.3 needs one round trip less to connect and leaves out the old ciphers; current nginx, Apache and Caddy versions enable it by default.

Does the check request a page from my site?

No — it only completes a TLS handshake on port 443, from our test server in Amsterdam, and then closes the connection. To see redirects, response headers and timings, use the HTTP header checker.

More free tools

All tools