SSL Expiry Checker

This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.

Try:

About SSL Expiry Checker

The CSR.plus SSL Expiry Checker tells you exactly when a domain’s certificate expires and how many days remain. Enter a hostname, and the tool connects live and reads the certificate’s validity period, returning the issue date, expiry date, and a clear days-remaining countdown.

An expired SSL certificate takes down HTTPS, triggers browser warnings, and costs you traffic and trust. System administrators use this expiry checker to answer "when does my SSL certificate expire?" in seconds, to verify renewal work after it has been applied, and to catch certificates that a monitoring dashboard missed.

Why use

  • Get the exact expiry date and days remaining for any hostname
  • Verify a renewal was applied correctly after installation
  • Reads the live certificate — exactly what browsers receive
  • Works for any port, including non-standard HTTPS services

How to use

  1. Type the domain name you want to check (for example example.com).
  2. Set a custom port if the service is not on 443.
  3. The tool connects to the host and reads the server certificate’s validity period.
  4. See the issue date, expiry date, and a clear days-remaining countdown.

Frequently asked questions

▸How accurate is the expiry date?

It reads the certificate presented by the server live, so the dates reflect exactly what browsers receive.

▸Does it check subdomains?

It checks the exact host you enter; check each subdomain separately as they may use different certificates.

▸What happens if a certificate is already expired?

The result is clearly marked as expired so you know a renewal is overdue.

▸When should I renew my SSL certificate?

Best practice is to renew at least 14–30 days before expiry. Most certificate authorities now issue certificates for 90 days or less, so plan renewals accordingly.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.