SSL checker
Check that a site loads securely over HTTPS, when its certificate expires and who issued it, and whether HTTP redirects, HSTS and mixed content are set up right. Free, no account.
Enter a domain or any page on it.
How to check a website's SSL certificate
- 1
Enter the domain
Type the site, such as example.com or www.example.com. Check each hostname you use, since each needs its own certificate coverage.
- 2
Read the verdict
The checker loads the site over HTTPS, looks up the current certificate in the public certificate logs, and tests redirects, HSTS and mixed content.
- 3
Renew before it expires
If the certificate expires within 30 days, confirm auto-renewal is working or renew it with your host or certificate authority.
- 4
Close the gaps
Redirect http:// to https:// with a 301, add a Strict-Transport-Security header, and switch any http:// scripts, styles or images to https://.
Check the rest of the site too
The free audit checks HTTPS and security headers alongside crawlability, schema, links and AI-search readiness.
Frequently asked questions
What does an SSL checker test?
Whether the site loads over HTTPS with a certificate browsers trust, when that certificate expires and who issued it, which hostnames it covers, whether plain HTTP redirects to HTTPS, whether HSTS is on, and whether the page pulls in insecure http:// files.
Where do the certificate details come from?
From the public Certificate Transparency logs, via crt.sh. Every publicly trusted certificate has to be logged there, so the checker shows the most recently issued valid certificate that covers your hostname, which is normally the one your server is using.
What happens when an SSL certificate expires?
Browsers show a full-page security warning and most visitors leave. Search engines can't crawl the page securely either. Free certificates such as Let's Encrypt last 90 days and renew automatically, so an expiry usually means renewal has quietly broken.
What is mixed content?
An HTTPS page that loads some files over plain http://. Browsers block insecure scripts, styles and frames outright, which breaks parts of the page, and flag insecure images. The fix is to load every resource over https://.
What is HSTS?
Strict-Transport-Security is a response header telling browsers to use HTTPS for your site from then on, even if someone types http://. A max-age of at least 180 days is the usual minimum, and a year is needed for the browser preload list.