🔒 Public TLS certificate lookup

SSL Certificate Checker

Enter a hostname to inspect the certificate served on port 443: subject, issuer, SANs, validity, days remaining, and negotiated TLS version.

Certificate lookup

🌐
Honest note: The check runs on our server (port 443 only). Private, loopback, link-local, and reserved addresses are rejected. The hostname is sent to this API. We do not store the certificate.

Check TLS certificates without a terminal

See who issued a site’s certificate, which names it covers (SANs), when it expires, and which TLS version the server negotiated with us. Useful before renewals and when debugging browser warnings.

Results reflect the certificate presented to our server at the moment of the request. CDNs and multi-SAN certs are common — the SAN list is the authoritative set of names, not just the common name.

Frequently asked questions

Does this work for localhost or private IPs?

No. Only public hostnames and public IPs are accepted, to prevent SSRF.

Which port is checked?

Port 443 only. This is not a general TLS scanner.

What if the certificate fails verification?

We still try to show subject, issuer, SANs, and dates, and flag the verification error.

Is the certificate stored?

No. The lookup is live and the response is not stored by this tool.