Website & Technical3 min read
How to Check an SSL Certificate for Free
An expired certificate replaces your site with a browser warning. Here is what a certificate actually proves, and how to check yours before a visitor does it for you.
KLYRO TeamPublished
The padlock in a browser's address bar means one thing: the connection to that site is encrypted, and the certificate the server presented is trusted and matches the address you asked for.
When a certificate expires or stops matching, the browser does not show a small warning. It replaces the page with a full-screen interstitial telling people the site may not be safe. Most of them leave.
What a certificate actually proves
A certificate does two jobs, and it is worth being clear about which is which.
- It carries the public key that lets your browser set up an encrypted connection, so nobody between you and the server can read the traffic.
- It is signed by an authority the browser already trusts, which is what stops anyone presenting a certificate for a domain they do not control.
What it does not do is say anything about the site itself. A certificate is not a judgement about whether a business is legitimate, whether its code is secure or whether its content is honest. It says the connection is private and the name matches.
How to check a certificate
Enter the domain
A bare domain such as
example.comis enough. Klyro opens a TLS connection to it and reads the certificate the server presents.Check the verdict first
The summary line says whether the certificate is valid, expiring soon, expired, untrusted or for the wrong hostname. Everything below explains why.
Read the dates and the names
Confirm the expiry date is far enough away, and that the list of names it covers includes the exact address people use.
What to look for
- Days remaining. Most certificates today last 90 days and renew automatically. Automation fails quietly, so a number that keeps shrinking week after week is the signal that something stopped running.
- The names it covers. A certificate for
example.comdoes not automatically coverwww.example.com. If both addresses are in use, both need to be on the certificate. - Who issued it. A certificate from an authority your browser does not know produces the same warning as an expired one.
- Whether it is trusted. A self-signed certificate encrypts perfectly well and is still refused by every browser, because nothing vouches for it.
Common mistakes
- Assuming automatic renewal is working because it worked last time. A renewal that fails usually fails silently.
- Covering the bare domain but not
www, or the other way round, when both are reachable. - Renewing the certificate but not restarting the service that holds it, so the old one is still being served.
- Treating the padlock as a security assessment. It is a statement about the connection, not about the site.
Questions
- Is this a security scan?
- No, and the tool says so on the page. It reads the certificate a domain presents and reports what is in it. It does not test your server's configuration, look for vulnerabilities or assess your site in any other way.
- My certificate is valid but visitors still see a warning. Why?
- Usually because the address they are using is not one the certificate covers, or because the server is sending an incomplete chain. Check the list of covered names first, then whether the address redirects somewhere unexpected.
- How long should a certificate last?
- Most are issued for 90 days now, on the basis that a short life forces renewal to be automated. What matters is not the length but whether the renewal actually runs.