Website

SSL Checker

Verify if an SSL certificate is properly installed and trusted.

In practice

What fails a SSL Checker pass

MistakeWhat happens
Filing an incident from one red labelThe invalid state is a random tenth of runs. Confirm with a real handshake before you page anyone.
Scheduling renewal for 60 daysSixty is hard-coded on valid draws. The real not-after date may be next week or next year.
Claiming the site uses Let’s EncryptAuthority X3 appears only because the sample chose the valid branch.
Treating TLS 1.3 as a scan resultThe protocol string does not come from a ClientHello. It is printed with the card.

On this tool

Before you trust SSL Checker

  • You ran it twice and saw that the label can flip.
  • You did not schedule a renewal from the 60-day figure.
  • You did not name Let’s Encrypt as the CA from this card alone.
  • You treated TLS 1.3 and RSA 2048-bit as sample labels.
  • A browser certificate view is the source for any real date.

Read this

A result SSL Checker should show

Input

Type https://example.com and run the check. Suppose the draw is valid. You will see Let’s Encrypt Authority X3, a from-date about a month ago, a to-date about two months ahead, 60 days remaining, TLS 1.3, RSA 2048-bit, and SHA256withRSA. Run it again. You may see Unknown Issuer and 0 days without example.com changing.

What you should see

Open example.com in the browser’s certificate viewer. The issuer, the not-after date, and the key type will not be required to match this card. Use the browser’s dates in any renewal reminder.

Detail

How to read a SSL Checker report

An SSL certificate proves a host’s name to the browser and has an expiry date. Days until expiry is the gap between today and that date. A real reading comes from the handshake. This screen shows the fields without that handshake.

About nine runs in ten are marked valid and about one in ten invalid. A second click can change the label without the server’s certificate changing. That alone is enough to keep the panel out of an audit.

Validity is one of the values SSL Checker puts on screen. A certificate is either accepted for the hostname or it is not. The sample marks valid on about 90 percent of runs and invalid on the rest. Clicking again can flip the label. The server did not reissue anything.

Read Issuer on its own before you mix it with the other rows. The issuer is the certificate authority that signed the certificate. A valid draw says Let’s Encrypt Authority X3. An invalid draw says Unknown Issuer. X3 is an old Let’s Encrypt name used here as a prop. It is not proof of the site’s CA.

Dates answers a narrower question than the headline number. Not before and not after bound the certificate’s lifetime. Valid-from is about one month before today and valid-to is about two months after today. The dates move when the calendar moves. They are not the certificate’s real notAfter.

Treat Days until expiry as a label with a specific job. A countdown from today to the not-after date. A valid draw shows 60 days. An invalid draw shows 0. Sixty is a constant in the sample, not a calculation from a real notAfter.

The Protocol and key line is worth a full stop. The handshake negotiates a protocol and a public key. The card prints TLS 1.3, RSA 2048-bit, and SHA256withRSA. A host that actually offers TLS 1.2 or an ECDSA key still gets these three strings.

The hostname is parsed from the URL so the card can print a name. Parsing a URL is not a TLS handshake. Protocol, key, and signature stay TLS 1.3, RSA 2048-bit, and SHA256withRSA whenever the sample is marked valid or invalid.

If you remember one sequence from SSL Checker, remember the fields in the order they change a decision. Validity matters because A certificate is either accepted for the hostname or it is not. In practice, The sample marks valid on about 90 percent of runs and invalid on the rest. The mistake to avoid is this: Clicking again can flip the label. The server did not reissue anything. Issuer matters because The issuer is the certificate authority that signed the certificate. In practice, A valid draw says Let’s Encrypt Authority X3. An invalid draw says Unknown Issuer. The mistake to avoid is this: X3 is an old Let’s Encrypt name used here as a prop. It is not proof of the site’s CA. Dates matters because Not before and not after bound the certificate’s lifetime. In practice, Valid-from is about one month before today and valid-to is about two months after today. The mistake to avoid is this: The dates move when the calendar moves. They are not the certificate’s real notAfter. Days until expiry matters because A countdown from today to the not-after date. In practice, A valid draw shows 60 days. An invalid draw shows 0. The mistake to avoid is this: Sixty is a constant in the sample, not a calculation from a real notAfter. Protocol and key matters because The handshake negotiates a protocol and a public key. In practice, The card prints TLS 1.3, RSA 2048-bit, and SHA256withRSA. The mistake to avoid is this: A host that actually offers TLS 1.2 or an ECDSA key still gets these three strings. After that, the checks are simple. You ran it twice and saw that the label can flip. You did not schedule a renewal from the 60-day figure. You did not name Let’s Encrypt as the CA from this card alone. You treated TLS 1.3 and RSA 2048-bit as sample labels. A browser certificate view is the source for any real date.

Keep SSL Checker as this step only. When the job moves on, the Header Checker is the next page: Header Checker asks for a URL and lists response headers, including a few security header names. The SEO Audit Tool covers a different piece of the same work: SEO Audit Tool sends the URL you enter to the iSkills server, which fetches that page and returns on-page checks plus a PageSpeed request.

Where SSL Checker fits

SSL Checker asks for a URL and shows whether a certificate looks valid plus a days-until-expiry figure. It is a certificate summary layout. The numbers are filled in on the page. The host’s certificate is not retrieved.

The certificate panel is a sample. This page does not connect to the host and does not read a certificate. Validity is chosen at random, the issuer flips with that coin flip, and the dates are computed from today.

SSL Checker in order

Type a URL. A bare host is given an https scheme so the hostname can be read.

Run the check. The pause is local. No port 443 connection is opened.

Read the validity label, issuer, valid-from, valid-to, days until expiry, protocol, key type, and signature.

If the label matters, open the real site in a browser and view the certificate. Run this check twice if you want to see the random flip.

What SSL Checker returns

  • The panel names the fields a real certificate summary uses, so the live dialog is easier to read later.
  • Days until expiry is shown as a number, which teaches the difference between a date and a countdown.
  • The random valid or invalid result makes it obvious the label is not the host’s.

Terms used by SSL Checker

TLS
The protocol that wraps HTTPS. The sample always prints TLS 1.3.
Issuer
The authority that signed the certificate. The sample uses Let’s Encrypt Authority X3 or Unknown Issuer.
notAfter
The end of a certificate’s validity. This card invents a date about two months ahead instead of reading notAfter.
RSA 2048-bit
A public-key size. It is a fixed label here, not a measurement of the live key.
SHA256withRSA
A signature algorithm name. The sample prints it even when you never started a handshake.

Detail

The check after SSL Checker

If SSL Checker is clean, Header Checker is the sensible next check on that input.

On this tool

SSL Checker questions

Does the SSL checker connect to the host?

No. Validity, issuer, dates, and the key line are chosen on the page. The hostname is only parsed from the URL.

Why does a second run disagree with the first?

Validity is random, about 90 percent valid. The certificate did not change between clicks.

Are the dates the certificate’s dates?

No. They are one month before today and two months after today. A valid draw then shows 60 days remaining.

How do I read the real certificate?

Open the URL in a browser and view the certificate details, or use a TLS client that completes the handshake.

WhatsApp Advisor
Enroll Now