CloudSpex

Free SSL tool

Free SSL Certificate Checker

Read a website’s certificate, test which TLS versions it accepts, and get a health score and grade from one read-only handshake.

CloudSpex reports the certificate, its expiry, the names it covers, the chain, the negotiated cipher and the TLS versions the server accepts — and says plainly when something could not be measured.

Enter a domain such as example.com or paste a full HTTPS URL.

What is an SSL certificate checker?

An SSL certificate checker reviews whether a website can establish a trusted HTTPS connection for its hostname. It is a fast way to spot public certificate or HTTPS availability issues before they affect visitors.

What does CloudSpex check?

Certificate

Issuer, subject, the validity window and the exact days remaining, with the severity rising as expiry approaches.

Hostname and SAN

The full Subject Alternative Name list and whether it covers the hostname you checked, with RFC 6125 wildcard rules applied so a single wildcard is never stretched across two labels.

TLS versions

TLS 1.3, TLS 1.2, TLS 1.1 and TLS 1.0 are probed separately. A version is only reported as disabled when the server actually refuses it; anything the check could not determine is shown as not assessed.

Chain

The certificate chain is reported as trusted, self-signed, incomplete or not verified — stated against the trust store used for the check rather than as a universal verdict.

Cipher

The cipher suite this handshake negotiated, classified as modern, legacy or weak. Full cipher enumeration is reported as not assessed.

OCSP stapling

Whether the server staples a revocation response. Revocation status itself is never claimed without being verified.

Why SSL certificates fail

The common causes are an expired certificate, a certificate that does not list the hostname being visited, a chain missing its intermediate, or a self-signed certificate left over from a staging setup. A missing intermediate is the one that looks intermittent: some browsers fetch it themselves and appear fine while API clients fail outright. Each of these is reported separately here, with the certificate dates and the names on the certificate shown so you can see which case you have.

SSL check vs SSL monitoring

One-time check

Shows the certificate, protocols and grade as they are right now. Run it again manually after a change.

Continuous monitoring

Tracks certificate expiration, HTTPS availability and related configuration changes for monitored domains.

Frequently asked questions

What is an SSL certificate checker?

An SSL certificate checker makes a read-only HTTPS connection to assess whether a website certificate can be reached and validated for its hostname. It helps identify certificate and HTTPS availability issues before visitors encounter browser warnings.

What does the CloudSpex SSL checker test?

It reads the certificate itself — issuer, subject, Subject Alternative Names, validity dates and days remaining — checks that the hostname is covered, examines the chain, tests TLS 1.0, 1.1, 1.2 and 1.3 separately, reports the negotiated cipher and whether OCSP stapling is enabled, then scores the result out of 100 with a grade from A+ to F.

Is this an SSL checker or a TLS checker?

Both, because they are the same connection. SSL is the historical name; the protocol in use today is TLS. This page reports the certificate — which people look for under “SSL” — and the protocol versions and cipher, which people look for under “TLS”, from one read-only handshake.

Does CloudSpex show the certificate expiration date?

Yes. The result shows the validity window and the number of days remaining, and it raises a finding as the expiry approaches: a warning inside 60 days, high inside 30 and 14, and critical inside 7 days or once the certificate has expired.

How is the TLS grade calculated?

The grade comes from fixed rules, not from the score alone. An expired certificate, a hostname mismatch, an untrusted chain or a self-signed certificate is an F regardless of anything else. TLS 1.0 caps the grade at C and TLS 1.1 caps it at B, so a high score cannot hide a deprecated protocol. A+ requires every critical field to have been measured and passed.

Why does the page say “Not assessed” instead of “Disabled”?

Because they mean different things. Disabled means the server actively refused that protocol version, which is a real measurement. Not assessed means the check could not determine the answer — the runtime could not offer that version, or the handshake failed for an unrelated reason. Showing an unmeasured version as disabled would report a protection that was never verified, so it is never done here.

Does this test every cipher the server supports?

No, and it does not claim to. A single handshake shows the one cipher suite the server and client agreed on. The page reports that negotiated cipher and marks full cipher enumeration as not assessed, rather than implying the server supports nothing else.

Does this check whether the certificate has been revoked?

No. The page reports whether OCSP stapling is enabled, which is observable from the handshake, but it does not validate the stapled response or query the certificate authority. A revocation status that has not been verified is never reported as good.

How are wildcard certificates handled?

According to RFC 6125: a wildcard matches exactly one label. A certificate for *.example.com covers api.example.com but does not cover foo.bar.example.com, and does not cover example.com itself. When a certificate carries Subject Alternative Names, the Common Name is not used as a fallback, which is also what browsers do.

What does an invalid SSL certificate mean?

An invalid certificate can cause browsers to warn visitors that a connection is not private. Review the certificate deployment, DNS and HTTPS origin configuration before checking again.

Can a website use HTTPS and still have a certificate problem?

Yes. A website can respond over HTTPS while certificate validation still needs attention. This checker reports the public SSL and HTTPS signals it can safely assess.

Is this SSL certificate check free?

Yes. The public SSL certificate check is free and uses a limited, read-only scan.

Does the SSL checker make changes to the website?

No. It reads public-facing HTTPS signals only. It does not change certificates, DNS, website files or server configuration.

How often should SSL certificates be checked?

Run a check after certificate, hosting, DNS or CDN changes. Continuous monitoring is useful for catching expiration and HTTPS availability changes between manual checks.

SSL issues can appear after configuration changes.

Add your domain to CloudSpex to monitor HTTPS availability, certificate validation and related domain configuration changes.

Start Monitoring Free