Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

SSL Certificate Checker

Is HTTPS set up right? Certificate trust, redirects, HSTS, mixed content and CT logs.

Network Uses live data Free, no sign-up

Check a site’s HTTPS

Checks https://host/ from Cloudflare’s network with full certificate validation, plus the HTTP→HTTPS redirect, HSTS and mixed content. Certificate details come from public Certificate Transparency logs.

Next steps

About the SSL Certificate Checker

Enter a host name and the checker connects to it over HTTPS from Cloudflare’s network with full certificate validation — the same strict check a browser makes — then reports whether the certificate is trusted, whether plain HTTP redirects to HTTPS, how the site’s HSTS header is set, whether the site is on the browsers’ HSTS preload list, and which resources on the page still load over http:// (mixed content). Every finding says what it means and how to fix it.

Web pages and serverless functions cannot read a server’s certificate directly, so the issuer, names and validity dates come from Certificate Transparency logs (RFC 6962), searched through crt.sh. Chrome and Safari only trust certificates that have been logged, so the logs show what has been issued for the name and how many days each certificate has left.

How to use it

  1. Type a host name such as example.com, or paste a URL — only the host is used.
  2. Press Check certificate. The server check takes a few seconds; the Certificate Transparency search on crt.sh can take up to a minute.
  3. Read the findings from top to bottom. Fail and Warn items say what to change; Pass and Info items confirm what is set up.
  4. Open HSTS preload requirements before submitting to hstspreload.org, and Insecure references on the page to find each http:// resource with its line number.
  5. Press Copy report to send the results to your developer or hosting provider.

Examples

A well-configured site (illustration)
Result
PASS Certificate accepted
PASS HTTP redirects to HTTPS — 301 → https://example.com/
PASS HSTS on: max-age 2 years · includeSubDomains, preload
INFO Not on the HSTS preload list
PASS No mixed content found
CT logs: 90-day certificate, 83 days left (limit when issued: 200 days)
An expired or wrong-name certificate (illustration)
Result
FAIL Certificate rejected (error 526)
INFO Mixed content not checked

Browsers show a full-page warning for these sites. Renew the certificate, make sure it lists every name you use (with and without www), and serve the intermediate certificate too.

Common uses

  • Confirming a new or renewed certificate works before customers notice a warning.
  • Checking that http:// visitors are redirected and HSTS is in place after moving to HTTPS.
  • Finding the images, scripts and stylesheets that cause “not fully secure” warnings.
  • Reviewing a site’s readiness for the HSTS preload list.

What is checked, and how

  • Certificate trust: Cloudflare Workers make outside requests in Full (strict) SSL mode, so an expired, self-signed, wrong-name or untrusted certificate makes the request fail with error 526 (525 when the TLS handshake itself fails), as documented in Cloudflare’s error 526 guide. A missing intermediate certificate is not reliably caught: Cloudflare, like Chrome, can complete the chain itself (incomplete-chain.badssl.com passed this check on 3 October 2026), although some apps and older devices reject such a server.
  • HTTP → HTTPS: one request to http://host/ without following redirects; a permanent redirect to https:// on the same host is what you want.
  • HSTS: the Strict-Transport-Security header on the first HTTPS response, read the way RFC 6797 says browsers must (a valid max-age is required, each directive only once, only the first header counts).
  • Preload list: the status from hstspreload.org, and the submission requirements it publishes, checked one by one.
  • Mixed content: the first 512 KB of the home page, classified as in the W3C Mixed Content specification: images loaded with src, audio and video are upgraded to https:// by browsers; scripts, stylesheets, frames, fonts and srcset images are blocked.

Certificate lifetimes are getting shorter

The CA/Browser Forum Baseline Requirements cap how long a publicly trusted TLS certificate may be valid, based on when it is issued (Baseline Requirements v2.3.0, §1.2.2, ballot SC-081):

  • issued before 15 March 2026: up to 398 days
  • from 15 March 2026: up to 200 days
  • from 15 March 2027: up to 100 days
  • from 15 March 2029: up to 47 days

Each certificate found in the logs is compared with the limit for its issue date. Shorter lifetimes make manual renewal impractical — use automatic renewal (ACME) through your host or CDN.

HSTS and the preload list

HSTS tells browsers to use HTTPS for a host for max-age seconds after a visit, so later http:// links are upgraded before anything is sent. A typical header is Strict-Transport-Security: max-age=31536000; includeSubDomains. hstspreload.org asks that sites raise max-age gradually and test every subdomain before going to a year.

To be preloaded (built into browsers, so even the first visit is protected), hstspreload.org requires a valid certificate, a redirect from HTTP to HTTPS on the same host if port 80 is open, HTTPS on every subdomain, and on the base domain a header with max-age of at least 31536000, includeSubDomains and preload — also on any redirect. It warns that inclusion cannot easily be undone. Some TLDs are preloaded as a whole: .dev, .app and .page among them.

Limitations

  • The certificate the server presents (its chain, exact expiry, key type) cannot be read from a web page or a Cloudflare Worker, so details come from Certificate Transparency logs, which list every certificate issued for the name — not necessarily the one in use.
  • TLS versions, cipher suites and revocation are not tested: that needs raw connections, which this free browser-and-serverless setup does not have. A server that leaves out its intermediate certificate can also pass, because Cloudflare completes the chain itself.
  • crt.sh is a free community service: it often takes 15–60 seconds and is sometimes unavailable. Try again later if it fails.
  • Only the home page is scanned for mixed content, up to 512 KB of HTML; resources added later by scripts are not seen.
  • Only the standard ports (443, and 80 for the redirect check) and public hosts can be checked, and each visitor has an hourly limit.

Privacy

The host name is sent to MySmartCoPilot’s server, which requests https:// and http:// on that host (as MySmartCoPilotBot, without cookies) and asks hstspreload.org for its preload status. Your browser searches crt.sh for the host name. MySmartCoPilot does not store host names or results; its log records only the host, status code and time of each request.

Frequently asked questions

How do I see when my SSL certificate expires?

The Certificate Transparency list shows the days left for each unexpired certificate; the newest one is usually the one in use. To read the certificate your server actually presents, run openssl s_client -connect example.com:443 -servername example.com </dev/null | openssl x509 -noout -dates or open the padlock in your browser.

What does error 526 mean?

The certificate could not be validated: it has expired, it does not list the host name, it is self-signed or issued by an untrusted authority, or its chain to a trusted root could not be completed. If the site is behind Cloudflare, the failing certificate may be the one on the origin server, and visitors see Cloudflare’s 526 error page.

The checker says the certificate is fine, but my browser warns. Why?

Check that the browser opened the same host (www and non-www can have different certificates), that your device’s clock is right, and that no antivirus or company proxy is intercepting HTTPS. Very old devices may also lack newer root certificates.

Should I add my site to the HSTS preload list?

Only when every subdomain — including internal ones — works over HTTPS for good. Preloading protects even the first visit, but removal takes months to reach browsers. A long max-age with includeSubDomains already protects returning visitors.

What is mixed content?

An HTTPS page that loads something over plain http://. Browsers block scripts, stylesheets, frames and fonts loaded that way and try to upgrade images, audio and video to https://. Change those URLs to https://, or add upgrade-insecure-requests to your Content-Security-Policy while you fix them.

Why are there several certificates for my domain?

Renewals overlap, sites with several servers may use separate certificates, and CDNs such as Cloudflare often keep backup certificates from a second certificate authority. All unexpired ones are valid; the server decides which to present.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.