How to use
- 1Enter the domain (e.g. example.com) — no https:// needed.
- 2Press “Check” to test the HTTPS connection and look up the certificate.
- 3See the verdict, issuer, validity dates and days remaining.
- 4Check covered names, HSTS and whether http:// redirects to https://.
What this SSL check covers
We make a real HTTPS connection to the host to confirm it works, check for an HSTS header and test whether plain http:// redirects to https://. Certificate details — issuer, not-before and not-after dates and the Subject Alternative Names (SAN) — come from public Certificate Transparency logs, where every publicly trusted certificate must be recorded. Days remaining turn yellow under 30 and red under 14.
Certificate lifetimes are getting shorter
Publicly trusted certificates are capped at 398 days, and the CA/Browser Forum has approved a phased reduction: 200 days from March 2026, 100 days from March 2027 and 47 days from March 2029. Free Let’s Encrypt certificates already last 90 days. In practice this means manual renewal no longer works — use automated renewal (ACME/certbot, or your host or CDN’s auto-SSL) and monitor expiry.
Fixing common SSL errors
NET::ERR_CERT_DATE_INVALID means the certificate expired (or the visitor’s clock is wrong) — renew it and reload the web server. NET::ERR_CERT_COMMON_NAME_INVALID means the hostname isn’t in the SAN list; www and the bare domain need to be covered separately unless you use a wildcard. Incomplete-chain errors, common on Android, mean the server isn’t sending the intermediate certificate: install the full chain (fullchain.pem) instead of just the leaf.
Frequently asked questions
Is a free SSL certificate as secure as a paid one?
Yes. Domain-validated certificates from Let’s Encrypt use the same encryption as paid DV certificates. Paid OV/EV certificates add organization vetting, not stronger encryption, and browsers no longer show EV names in the address bar.
Does a wildcard certificate cover the bare domain?
No. *.example.com covers www.example.com and shop.example.com but not example.com itself or deeper levels like a.b.example.com. Most CAs add the bare domain as a second name.
What is HSTS and should I enable it?
HSTS tells browsers to always use HTTPS for your domain, preventing downgrade attacks. Enable it once HTTPS works everywhere, starting with a short max-age and raising it to one year.
Does SSL affect Google rankings?
HTTPS is a lightweight ranking signal, and Chrome labels http pages “Not secure”, which hurts trust and conversions far more than the ranking effect.
Not happy with the results?
Talk to Webin Agency about fast, SEO-friendly websites, e-commerce and Google Ads management.