Certificate
Issuer, subject, the validity window and the exact days remaining, with the severity rising as expiry approaches.
Free SSL tool
Read a website’s certificate, test which TLS versions it accepts, and get a health score and grade from one read-only handshake.
CloudSpex reports the certificate, its expiry, the names it covers, the chain, the negotiated cipher and the TLS versions the server accepts — and says plainly when something could not be measured.
An SSL certificate checker reviews whether a website can establish a trusted HTTPS connection for its hostname. It is a fast way to spot public certificate or HTTPS availability issues before they affect visitors.
Issuer, subject, the validity window and the exact days remaining, with the severity rising as expiry approaches.
The full Subject Alternative Name list and whether it covers the hostname you checked, with RFC 6125 wildcard rules applied so a single wildcard is never stretched across two labels.
TLS 1.3, TLS 1.2, TLS 1.1 and TLS 1.0 are probed separately. A version is only reported as disabled when the server actually refuses it; anything the check could not determine is shown as not assessed.
The certificate chain is reported as trusted, self-signed, incomplete or not verified — stated against the trust store used for the check rather than as a universal verdict.
The cipher suite this handshake negotiated, classified as modern, legacy or weak. Full cipher enumeration is reported as not assessed.
Whether the server staples a revocation response. Revocation status itself is never claimed without being verified.
The common causes are an expired certificate, a certificate that does not list the hostname being visited, a chain missing its intermediate, or a self-signed certificate left over from a staging setup. A missing intermediate is the one that looks intermittent: some browsers fetch it themselves and appear fine while API clients fail outright. Each of these is reported separately here, with the certificate dates and the names on the certificate shown so you can see which case you have.
Shows the certificate, protocols and grade as they are right now. Run it again manually after a change.
Tracks certificate expiration, HTTPS availability and related configuration changes for monitored domains.
An SSL certificate checker makes a read-only HTTPS connection to assess whether a website certificate can be reached and validated for its hostname. It helps identify certificate and HTTPS availability issues before visitors encounter browser warnings.
It reads the certificate itself — issuer, subject, Subject Alternative Names, validity dates and days remaining — checks that the hostname is covered, examines the chain, tests TLS 1.0, 1.1, 1.2 and 1.3 separately, reports the negotiated cipher and whether OCSP stapling is enabled, then scores the result out of 100 with a grade from A+ to F.
Both, because they are the same connection. SSL is the historical name; the protocol in use today is TLS. This page reports the certificate — which people look for under “SSL” — and the protocol versions and cipher, which people look for under “TLS”, from one read-only handshake.
Yes. The result shows the validity window and the number of days remaining, and it raises a finding as the expiry approaches: a warning inside 60 days, high inside 30 and 14, and critical inside 7 days or once the certificate has expired.
The grade comes from fixed rules, not from the score alone. An expired certificate, a hostname mismatch, an untrusted chain or a self-signed certificate is an F regardless of anything else. TLS 1.0 caps the grade at C and TLS 1.1 caps it at B, so a high score cannot hide a deprecated protocol. A+ requires every critical field to have been measured and passed.
Because they mean different things. Disabled means the server actively refused that protocol version, which is a real measurement. Not assessed means the check could not determine the answer — the runtime could not offer that version, or the handshake failed for an unrelated reason. Showing an unmeasured version as disabled would report a protection that was never verified, so it is never done here.
No, and it does not claim to. A single handshake shows the one cipher suite the server and client agreed on. The page reports that negotiated cipher and marks full cipher enumeration as not assessed, rather than implying the server supports nothing else.
No. The page reports whether OCSP stapling is enabled, which is observable from the handshake, but it does not validate the stapled response or query the certificate authority. A revocation status that has not been verified is never reported as good.
According to RFC 6125: a wildcard matches exactly one label. A certificate for *.example.com covers api.example.com but does not cover foo.bar.example.com, and does not cover example.com itself. When a certificate carries Subject Alternative Names, the Common Name is not used as a fallback, which is also what browsers do.
An invalid certificate can cause browsers to warn visitors that a connection is not private. Review the certificate deployment, DNS and HTTPS origin configuration before checking again.
Yes. A website can respond over HTTPS while certificate validation still needs attention. This checker reports the public SSL and HTTPS signals it can safely assess.
Yes. The public SSL certificate check is free and uses a limited, read-only scan.
No. It reads public-facing HTTPS signals only. It does not change certificates, DNS, website files or server configuration.
Run a check after certificate, hosting, DNS or CDN changes. Continuous monitoring is useful for catching expiration and HTTPS availability changes between manual checks.
Add your domain to CloudSpex to monitor HTTPS availability, certificate validation and related domain configuration changes.
Start Monitoring Free