Certificate Revocation Checker
This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.
Checks Certificate Revocation Lists (CRL) and shows OCSP responder URLs.
About Certificate Revocation Checker
The CSR.plus Certificate Revocation Checker verifies whether a certificate has been revoked before its expiry date. Enter a domain or paste a certificate, and the tool inspects the CRL distribution points and surfaces the embedded OCSP responder URLs so you can confirm the certificate is still trusted.
A certificate can be revoked because its key was compromised, the domain changed hands, or a CA decided to invalidate it — long before the printed expiry date. This online revocation checker is used by administrators and security analysts to answer "has this certificate been revoked?" and to verify that CRL and OCSP mechanisms are properly embedded in the certificates they issue.
Why use
- Check revocation status via CRL distribution points and OCSP endpoints
- Detect certificates invalidated before their expiry date
- Verify a CA embedded working CRL/OCSP URLs in your certificates
- Paste any certificate or check a live host by domain
How to use
- Enter the domain to check, or paste the certificate you want to verify.
- The tool reads the CRL distribution points and OCSP responder URLs from the certificate.
- It fetches the listed CRL or queries the OCSP responder for the serial number.
- Review the verdict: revoked, good, or unverifiable (no revocation mechanism present).
Frequently asked questions
▸What is the difference between CRL and OCSP?
CRL is a periodically published list of revoked serial numbers; OCSP is a real-time query to the issuer’s responder.
▸Why check revocation?
A certificate can be compromised and revoked before it expires; revocation checks reveal that status.
▸What if there is no CRL or OCSP?
The tool reports that no revocation mechanism is embedded, meaning revocation cannot be verified from the certificate alone.
▸Do browsers check revocation?
Modern browsers have largely stopped blocking on OCSP for performance reasons. This makes independent revocation checking more important for security teams.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
Certificate / Key Matcher
Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.
PEM Viewer
Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.
SSL Format Converter
Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
Let's Encrypt Checker
Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
CAA Record Checker
Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.
SSL Handshake Tracer
Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.