FREE TOOL · NO SIGNUP

SSL Check: valid, secure, renewed in time?

Check a domain’s TLS certificate in 2 seconds — issuer, remaining lifetime, cipher suites, browser compatibility, OCSP stapling.

★★★★★ 4.9 / 5 · 88 reviews
A+
Rating
2s
per check
TLS 1.3
tested
TOOL · 08 / 09
SSL Check
Cert · Cipher · OCSPFREE

By using this tool you agree to our Terms and Privacy Policy

Your data is safe

No storage

Domains are only used for the check and discarded immediately.

Public data

Only publicly accessible SSL certificates and HTTP headers are queried.

No account needed

The tool works completely anonymously and without signup.

GDPR compliant

No personal data, no storage, no sharing.

SSL CHECK — THE GUIDE

What does the SSL check verify?

ON THIS PAGE
  1. What is SSL Check?
  2. Why do you need this?
  3. Step-by-step in 4 steps
  4. What gets checked?
  5. Glossary
  6. FAQ

What does the SSL check verify?

TLS/SSL is the encryption between browser and server. An expired or weakly configured certificate causes browser warnings and SEO penalties. We check expiry, issuer, cipher suites and configuration in one step.

Why check SSL regularly?

An expired certificate is an instant outage:

  • Expiry. Browser blocks completely, conversion = 0.
  • SEO. Google penalises outdated TLS configurations.
  • Mixed content. External resources without HTTPS = warning.
  • Compliance. PCI-DSS, ISO 27001 require modern ciphers.

Step-by-step: SSL Check in 4 steps

  1. 1
    Enter a domain
    Domain only — port 443 is queried.
  2. 2
    Fetch the cert
    We open a TLS connection.
  3. 3
    Cipher test
    Which suites are supported?
  4. 4
    Rating
    A+ to F. Recommendations per gap.

What gets checked?

We use SSL Labs’ methodology as the baseline:

Certificate
Issuer, validity, remaining lifetime.
Cipher suites
Which ones are supported?
Protocol versions
TLS 1.0/1.1/1.2/1.3.
Heartbleed
Known vulnerabilities.
POODLE
SSLv3 vulnerability.
OCSP stapling
Faster validation.
HSTS
Force HTTPS.
CT logs
Certificate Transparency.
GLOSSARY

SSL/TLS vocabulary

TLS
Transport Layer Security — successor to SSL.
Cipher suite
Combination of encryption algorithms.
CA
Certificate Authority.
OCSP
Online Certificate Status Protocol.
HSTS
HTTP Strict Transport Security.
Mixed content
HTTPS page with HTTP resources.
Forward Secrecy
Session keys cannot be reconstructed.
CT log
Public certificate logbook.
WHO USES IT

Who checks SSL?

DevOps
Before every deploy.
Security
Quarterly audit.
Marketing
Before campaign launches.
Hosters
Cert renewal tracking.
Compliance
Audit trail for ISO/PCI.
FAQ

FAQ for SSL Check

When to renew?
30 days before expiry — with Let’s Encrypt automatically every 60 days.
What is A+?
Best possible rating — TLS 1.3 only, HSTS preload, Forward Secrecy.
Self-signed?
We mark it; outside intranets it’s a problem.
Wildcard cert?
Fully supported in the check.
Does it cost?
Web: €0. Monitoring: Mandokit plan.
Do you store cert data?
No, only the request ID for the audit trail.

Never miss an SSL expiry again.

Mandokit finds, validates and contacts B2B leads for you — as a guided workflow or via API.

Try for free