Free · instant · no signup to get a result

Check any site's SSL certificate.

Reads the live TLS certificate: who issued it, when it expires, whether it actually matches the domain, plus the six security headers that protect your visitors.

We open a live TLS connection on port 443 and read the certificate your server presents.

Opening a secure connection…
0
out of 100
 
 

Certificate & header findings

Common questions

What does this check?

It opens a real TLS connection to your server and reads the certificate it presents: who issued it, when it expires, whether it actually covers the domain you entered (including wildcard matching), whether it is self-signed, and which TLS version was negotiated. Then it reads the six security headers your server sends and reports which are missing.

My certificate expires soon. What happens if I let it lapse?

Every visitor gets a full-page browser warning telling them your site is not secure, and most will leave immediately. Search engines will also drop you. Renewal is usually automatic with Let's Encrypt — if yours is not automated, that is the real fix, not just renewing this once.

What does "certificate does not match this domain" mean?

The certificate the server presented was issued for a different hostname. This usually happens when a site is served from shared hosting without SNI configured properly, or when someone points a new domain at an old server. Browsers treat it as a hard failure, exactly as they would a forged certificate.

Why is my score capped even though most checks passed?

Because a broken certificate is not something good headers can compensate for. If the certificate is expired, self-signed, or does not match the domain, every visitor is being shown a security warning — so we cap the score rather than let a strong header configuration average it up into a passing grade.

Are the security headers really necessary?

They are not required for the site to work, which is exactly why most sites have none of them. They cost nothing to add and they close real attack paths: HSTS stops downgrade attacks, Content-Security-Policy is the strongest defence against injected scripts, and frame protection prevents clickjacking. If you handle logins or payments, treat them as mandatory.

Certificate problems? We manage this for our clients.

Every site we host gets an auto-renewing certificate and a proper security header baseline — so this check comes back clean without anyone having to remember a renewal date.

Talk to our team