SSL certificate checker

Check SSL certificate expiry for any domain. Free SSL checker using Certificate Transparency logs. Warn before HTTPS breaks.

SSL and TLS certificates encrypt traffic between browsers and your server. When a certificate expires, visitors see security warnings, APIs fail handshakes, and search engines may downgrade trust signals. An SSL checker helps you discover expiration dates before they cause downtime. Qikot queries public Certificate Transparency logs through crt.sh to find the latest certificate issued for your domain — no port scanning and no agent installation required.

Certificate Transparency is an open ecosystem where certificate authorities publish newly issued certs. That data includes the notAfter expiry timestamp. Our tool parses the most recent entry for your hostname and calculates days remaining. We flag warnings when expiry is within fourteen days and mark expired certificates as down so you can prioritize renewal with your hosting provider or ACME automation.

Modern certificates from Let's Encrypt often renew every ninety days; commercial certificates may last up to thirteen months. Staging domains, wildcard certs, and multi-domain SAN certificates all appear in CT logs when publicly trusted. If no certificate is found, you may be using a private CA, a very new issuance not yet logged, or a hostname typo — verify DNS and try again.

SSL monitoring complements uptime and domain expiry checks. A site can be up while serving an expired cert, breaking HTTPS for users even though HTTP health checks pass. Add SSL checks to your release checklist and include them on public status pages when communicating maintenance to customers.

Qikot's SSL checker is free, instant, and runs on our remote servers. We do not store your domains in a user database. Results cache for two minutes on our servers. For HTTPS troubleshooting beyond expiry, use our HTTP header checker to inspect Strict-Transport-Security and related security headers.

Read the guide →

Related article →