Let's Encrypt Certificate Checker - Issuer, 90-Day Countdown and Chain
Let's Encrypt Certificate Checker
Check whether your certificate is from Let's Encrypt, where it sits in its 90-day cycle and how healthy its chain is.
About Let's Encrypt Certificate Checker
The CSR.plus Let's Encrypt Certificate Checker tells you everything about a Let's Encrypt deployment in one click: whether the certificate was issued by Let's Encrypt (intermediates R3, R10, E5, E6 and friends), how far through its 90-day cycle it is, whether the chain is complete, and whether you are still serving the legacy cross-signed chain for old devices.
Because every Let's Encrypt certificate lives only 90 days, keeping track of where in the cycle you are is the difference between seamless renewal and an outage. This checker makes the countdown and chain health visible at a glance.
Why use
- Identifies the exact Let's Encrypt intermediate (R3, R10, E5, E6...) serving your site
- Visual 90-day cycle progress bar with days used and days remaining
- Chain completeness and legacy DST Root CA X3 cross-sign detection
- Concrete renewal and chain configuration advice
How to use
- Enter the domain whose certificate you want to inspect.
- Check the badge: is it a Let's Encrypt certificate, and which intermediate signed it?
- Read the 90-day progress bar to plan your renewal window.
- Review the chain status and follow the renewal advice.
Frequently asked questions
▸How do I know a certificate is from Let's Encrypt?
Let's Encrypt certificates are signed by the R3/R10 (or E5/E6) intermediates under ISRG Root X1. This checker inspects the leaf certificate's issuer and confirms it immediately.
▸When should I renew my Let's Encrypt certificate?
Renew once the certificate is past 60 days (roughly 60% through its 90-day cycle) and automated renewal is running. If you are below 30 days remaining, renew immediately.
▸What is the legacy cross-signed chain?
Before ISRG Root X1 became widely trusted, Let's Encrypt used a chain cross-signed by DST Root CA X3. Some very old Android/iOS/embedded devices still only trust that path; serving the cross-signed chain keeps them working.
▸Why is my chain reported incomplete?
Your server is not sending the intermediate certificate. ACME clients normally install the full chain automatically; if it is incomplete, download the intermediate and add it to your server configuration.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
Certificate / Key Matcher
Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.
PEM Viewer
Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.
SSL Format Converter
Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
CAA Record Checker
Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.
Certificate Revocation Checker
Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.
SSL Handshake Tracer
Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.