SSL Expiry Checker
See at a glance when your certificates run out. Enter up to ten host names, and the checker connects to each one, reads the certificate and lists the days remaining with the most urgent first. A calendar file with renewal reminders is one click away.
- Encrypted connection
- No sign-up
- Free to use
How to use SSL Expiry Checker
- Enter one host name per line, up to ten.
- Select Check expiry dates.
- Read the list, sorted by the days left and colour-coded by urgency.
- Open a row for the issuer and exact expiry time, or download the calendar file with reminders.
SSL Expiry Checker features
Bulk check
Up to ten hosts in one run, each with its own live connection.
Sorted by urgency
Expired and soon-to-expire certificates are at the top and shown in red.
Calendar reminders
Downloads an .ics file with an entry 14 days before each expiry, for any calendar app.
Trust and name check
Flags certificates that are not trusted or do not match the host, even when they have not expired.
Subdomain friendly
Check www, shop, mail and API hosts separately; they often use different certificates.
Per-host errors
A host that cannot be reached is reported on its own line without affecting the others.
When to use SSL Expiry Checker
- A weekly review of the certificates for all the sites and subdomains you operate.
- Checking a client's domains before taking over their hosting.
- Confirming that automatic renewal really replaced the certificate on every server.
- Setting calendar reminders for certificates that have to be renewed by hand.
SSL Expiry Checker FAQ
What happens when an SSL certificate expires?
Browsers replace the page with a security warning that most visitors will not click through. Apps, payment callbacks, API clients and email servers that connect to the host simply fail. The site is effectively offline until the certificate is renewed.
When should a certificate be renewed?
About 30 days before it expires. Automatic systems such as ACME clients for Let's Encrypt do this by themselves. If a certificate with automatic renewal shows fewer than 30 days, the renewal job is probably failing and deserves a look.
Why does the list show different dates for www and the bare domain?
They can be served by different servers or use separate certificates. It is common for the main site to sit behind a CDN while a subdomain points to another machine. Check every host name that people or systems actually connect to.
How does the calendar file work?
It contains an all-day event for each certificate, placed 14 days before the expiry date. Open the downloaded .ics file to import it into Google Calendar, Outlook, Apple Calendar or any other calendar program.
Is this a monitoring service?
No. It checks at the moment you ask and stores nothing. For continuous monitoring with alerts you need a service that runs checks on a schedule; the calendar reminders are a lightweight alternative.
Why does a certificate show days left but is still marked red?
Expiry is only one requirement. If the certificate is not trusted or does not match the host name, visitors get a warning regardless of the date, so the entry is flagged as urgent.
Keeping certificates from expiring unnoticed
Certificate expiry is one of the most avoidable causes of downtime, and it still catches large organisations every year. The reason is rarely that nobody knew certificates expire. It is that the renewal was automated long ago and then quietly broke: a DNS record changed, a validation path was blocked by a new firewall rule, a scheduled job disappeared during a server migration. Nothing looks wrong until the day the old certificate runs out.
A periodic look at the actual expiry dates is the simplest safeguard. With 90-day certificates and renewal at day 60, a healthy host should always show between 30 and 90 days remaining. A number below 30 is the early sign that automation has stopped, and it leaves a comfortable month to fix it. That is the rule the colour coding on this page follows.
Remember that a domain usually involves more than one certificate. The website, the www variant, a customer portal, the mail server and an API endpoint may each terminate TLS in a different place, with certificates issued and renewed independently. The one that gets forgotten is typically not the main site but a subdomain that someone set up once for a specific purpose.
For certificates that are renewed manually, such as those bought for a year from a commercial authority, put the date where a person will see it. The calendar export creates one reminder per certificate two weeks ahead, which is enough time to order, validate and install the replacement.