Web tool / 12

SSL Certificate Checker

Inspect a public hostname’s verified TLS certificate, issuer, dates, cipher, and alternative names.

SSL Certificate Checker: TOEA resolves the public hostname, connects directly to port 443 with hostname verification, and reports the peer certificate and negotiated encrypted connection. Processed securely on demand.

Category
Web tools
Runs
On TOEA's server
Cost
Free · no sign-up
Availability
Ready to use
TLS certificate deskSafe public URL check

Opens a verified TLS connection to port 443 on a public hostname.

Expiry and renewal

Public certificates are getting shorter-lived. Under a CA/Browser Forum decision, the maximum validity has been falling in steps, to 200 days from March 2026 and to 47 days by 2029, and Let's Encrypt certificates have long lasted 90 days. At those lengths renewal has to be automated, so treat days remaining here as a check that the automation works, and investigate if a certificate is inside its last few weeks without having renewed.

When browsers and other clients disagree

A server must send its certificate together with the intermediate certificates that link it to a trusted root. If an intermediate is missing, desktop browsers often fetch it themselves and show no error, while apps, API clients, and curl fail. A verification error here with a working browser usually means an incomplete chain. If a renewal is refused instead, check the domain's CAA records with the DNS lookup. Also check the names: a wildcard such as *.example.com covers shop.example.com but neither example.com itself nor a.b.example.com.

How to use it

  1. Enter a website URL or hostname.
  2. Choose Check certificate.
  3. Review verification, expiry, certificate identity, and negotiated TLS details.

Privacy & limitations

The hostname is checked through TOEA’s API and is not retained. The result reflects one connection from the API host and is not a complete TLS configuration or vulnerability audit.

Related tools

Frequently asked questions

Does this test every TLS version and cipher?

No. It reports the successful verified connection negotiated by the current API runtime.

Why might a certificate fail here but work elsewhere?

Networks, certificate chains, SNI behavior, regional endpoints, and trust stores can differ.

Free tool · runs on toea's server · no account required