How to use the SSL checker
Enter a domain such as example.com, or paste any web address, and press Check SSL. The checker connects to the site the same way a browser does and reports:
- Trust: whether browsers accept the certificate, meaning it's signed by a recognised certificate authority and the full chain is in place.
- Coverage: whether the certificate covers the exact name you entered. A certificate for
example.comdoesn't automatically coverwww.example.com. - Expiry: the exact date and the number of days left, with a warning when fewer than 30 remain.
- Details: issuer, key type, signature algorithm, TLS version, cipher and every certificate in the chain.
After the result, use the Check www too button to test the other version of the domain. Both should pass, even if one only redirects to the other, because the certificate is checked before any redirect happens.
Why SSL matters for SEO
HTTPS is a confirmed, if small, Google ranking signal, and Chrome labels pages without it as "Not secure". The bigger risk is an invalid certificate: an expired, mismatched or untrusted certificate triggers a full-page browser warning that stops almost every visitor, and Googlebot can't crawl the site normally until it's fixed. Checking certificates regularly, especially after moving hosts or adding a CDN, prevents that kind of sudden traffic drop.
Common SSL problems and fixes
| Problem | Usual fix |
|---|---|
| Certificate expired | Renew it. On cPanel, run AutoSSL; with Let's Encrypt, check that automatic renewal is working. |
| Name doesn't match | Reissue the certificate so it includes every name you use, such as both example.com and www.example.com. |
| Not trusted, chain incomplete | Install the intermediate certificate from your provider alongside your own certificate. |
| Self-signed | Replace it with a certificate from a trusted authority. Free options include Let's Encrypt and cPanel AutoSSL. |
| Old TLS version | Turn on TLS 1.2 and 1.3 in your server or CDN settings and turn off TLS 1.0 and 1.1. |
Certificates are getting shorter
Free certificates from Let's Encrypt already last only 90 days, and the industry has agreed to cut the maximum lifetime of all public certificates in stages over the next few years. Manual renewals will become impractical, so make sure renewal is automatic, and check your certificate here whenever you change hosting, DNS or CDN settings.
Frequently asked questions
How do I check when my SSL certificate expires?
Enter your domain above. The result shows the exact expiry date and how many days are left, and warns you when it's under 30 days.
Why does my site show 'Not secure' when it has a certificate?
Either the certificate is invalid (expired, for another name, or untrusted), or the page loads some images or scripts over http://. This tool checks the certificate; if it passes, look for mixed content on the page.
Does the certificate need to cover www?
Yes, if anyone visits the www version. Browsers check the certificate before following any redirect, so https://www.example.com needs a valid certificate even if it redirects to example.com.
Is a free SSL certificate as good as a paid one?
For encryption and SEO, yes. Browsers treat free Let's Encrypt and AutoSSL certificates exactly like paid ones. Paid certificates can add organisation validation or warranties.
Last updated
