Web tool / 12
SSL Certificate Checker
Inspect a public hostname’s verified TLS certificate, issuer, dates, cipher, and alternative names.
SSL Certificate Checker: TOEA resolves the public hostname, connects directly to port 443 with hostname verification, and reports the peer certificate and negotiated encrypted connection. Processed securely on demand.
- Category
- Web tools
- Runs
- On TOEA's server
- Cost
- Free · no sign-up
- Availability
- Ready to use
Expiry and renewal
Public certificates are getting shorter-lived. Under a CA/Browser Forum decision, the maximum validity has been falling in steps, to 200 days from March 2026 and to 47 days by 2029, and Let's Encrypt certificates have long lasted 90 days. At those lengths renewal has to be automated, so treat days remaining here as a check that the automation works, and investigate if a certificate is inside its last few weeks without having renewed.
When browsers and other clients disagree
A server must send its certificate together with the intermediate certificates that link it to a trusted root. If an intermediate is missing, desktop browsers often fetch it themselves and show no error, while apps, API clients, and curl fail. A verification error here with a working browser usually means an incomplete chain. If a renewal is refused instead, check the domain's CAA records with the DNS lookup. Also check the names: a wildcard such as *.example.com covers shop.example.com but neither example.com itself nor a.b.example.com.
How to use it
- Enter a website URL or hostname.
- Choose Check certificate.
- Review verification, expiry, certificate identity, and negotiated TLS details.
Privacy & limitations
The hostname is checked through TOEA’s API and is not retained. The result reflects one connection from the API host and is not a complete TLS configuration or vulnerability audit.
Related tools
Frequently asked questions
Does this test every TLS version and cipher?
No. It reports the successful verified connection negotiated by the current API runtime.
Why might a certificate fail here but work elsewhere?
Networks, certificate chains, SNI behavior, regional endpoints, and trust stores can differ.
Free tool · runs on toea's server · no account required