Home/Guides/How to Check SSL Certificate Expiry for a Domain
SSL/TLS troubleshooting

How to Check SSL Certificate Expiry for a Domain

Check the certificate actually served by the hostname users visit—not only the certificate you expect to be installed. Expiry, hostname coverage and endpoint routing all matter.

Short answer

To check a domain's SSL certificate expiry, connect to the exact HTTPS hostname, read the certificate validity end time and confirm the certificate also covers that hostname. The SSL Checker performs a verified TLS connection on port 443 and reports the expiry timestamp, days remaining, issuer, subject names and public IP used for the check.

Check the live endpoint, not only your certificate file

A certificate can be renewed successfully in a control panel while a load balancer, CDN edge, reverse proxy or old server still presents the previous certificate. Testing the public hostname shows what a client reaching that endpoint receives now.

Expiry date

The certificate's validity end timestamp tells you when that certificate stops being valid. Use automation rather than waiting for the final days before expiry.

Days remaining

A calculated remaining-days value is an operational aid. Renewal should happen with enough buffer to diagnose failed automation or incomplete deployment.

Hostname coverage

Review Subject Alternative Names to confirm the requested hostname is included. A certificate can be inside its date window and still be wrong for the domain.

Resolved endpoint

Compare the returned IP with the infrastructure you expect. DNS changes can send clients to a server that has a different certificate installed.

Why can a browser still show the old certificate after renewal?

The most common explanation is that the new certificate is not being served on every path. Check each reverse proxy, load balancer, CDN, web server and SNI virtual host that can terminate TLS. If DNS recently changed, verify both A and AAAA records and make sure IPv6 does not still point to an older endpoint.

What if the certificate is valid but the browser warns anyway?

Expiry is only one failure mode. A browser warning can also involve hostname mismatch, an incomplete or untrusted chain, local clock problems, interception software or a different endpoint than the one you tested. Treat the live certificate details as evidence, then diagnose the specific warning.

Certificate lifetimes are getting shorter

Shorter certificate lifetimes increase the importance of automated issuance, renewal and deployment. Do not build an operational process around manually checking one date at the last minute; monitor renewals and verify what production endpoints actually serve.

Primary references

Last technically reviewed: September 28, 2026.