Upcheck
Sign in
Free tool · No signup required

Check SSL certificate

Enter a hostname to see the SSL certificate it's actually serving right now — issuer, expiry, chain, and every field, free and instant.

What this tool does

A live read of the certificate a server presents

An SSL certificate check opens a real TLS connection to a hostname on port 443 and reads the certificate the server presents, the same handshake a browser performs. It returns the certificate's issuer, validity window, subject alternative names, key type and size, signature algorithm, and SHA-256 fingerprint — a live, one-time read of what that server is serving at the moment you check.

This check reflects the certificate the server is serving at this moment. For continuous coverage — so you find out the moment a certificate is renewed wrong or left to expire, not the next time you happen to check — Upcheck monitors it automatically every 12 hours.

Read on every check
Issuer & chainWhich CA signed it, down to the root
Common name & SANsEvery hostname the certificate covers
Valid from / expiresThe window, and days remaining
Signature algorithmHow the certificate was signed
Public keyType and size — RSA 2048, ECDSA P-256, and so on
SHA-256 fingerprintIdentifies this exact certificate
How it works

Three steps, no signup

01

Enter a hostname

Type a domain — with or without https:// — and submit it. No account, no install.

02

We open a real TLS connection

The checker connects on port 443 and reads the certificate the server actually presents, the same way a browser does.

03

Full certificate detail comes back

Issuer, validity window, SANs, key size, and fingerprint — not just a pass/fail.

FAQ

Frequently asked questions

How do I check an SSL certificate?

Type a hostname into the box above — a bare domain like example.com, or one with https:// in front — and click Check certificate. Upcheck opens a real TLS connection to the host and reads back the certificate it presents: issuer, expiry date, SANs, key size, and the rest, usually within a couple of seconds.

Is this SSL checker really free?

Yes. Checking a certificate here costs nothing and needs no account. Signing up is only for ongoing monitoring — having Upcheck re-check a hostname automatically every 12 hours and alert your team before its certificate expires.

Can I check any website, or only ones I own?

You can check any publicly reachable hostname's certificate, the same as opening it in a browser and clicking the padlock — you don't need to own it. Checks against non-public names like *.local or *.internal aren't supported, since those aren't reachable from the public internet this tool checks over.

Why does the tool show 'Host unreachable' or 'Invalid'?

Unreachable means the TLS handshake never completed — the host is down, DNS doesn't resolve, or nothing is listening on port 443. Invalid means a certificate came back but failed validation: a broken chain, a missing intermediate, or a name that doesn't match the host. Both are shown with the underlying error so you can see exactly what failed.

If I can check for free, why would I need certificate monitoring?

A single check is a snapshot of one moment. Certificates change — they get renewed, they get renewed wrong, or a validation step silently breaks and nobody notices until expiry takes the site down. Monitoring re-runs this same check automatically every 12 hours and alerts a person before that happens, which a one-off check by hand can't do.

Is there a limit to how many certificates I can check?

You can check as many hostnames as you like. Automated or scripted use is rate limited to keep the tool fast and available for everyone checking manually.

One check tells you now. Monitoring tells you before it matters again.

Add your hostnames to Upcheck and get alerted by email, Slack, Discord, Teams, or webhook — well before the next certificate lapses.