SSL / TLS Certificate Checker
Check any website's HTTPS certificate — expiry, issuer, chain, key, protocol and trust.
Certificate
Certificate chain
About the SSL / TLS Checker
The iHACKER SSL Certificate Checker connects to a website over TLS and reports everything about its HTTPS certificate in one place: the expiry date and days remaining, the issuer, the Subject Alternative Names it covers, the full certificate chain, the key type and size, the signature algorithm, the negotiated TLS protocol and cipher, and whether it's trusted and matches the hostname — each as a clear pass, warning or fail.
What it checks
- Expiry: days left, with warnings as renewal approaches.
- Hostname match: whether the certificate is valid for the domain you entered (wildcards included).
- Trust & chain: whether it verifies against public CAs and whether the intermediate chain is installed.
- Strength: flags weak keys (RSA under 2048-bit) and deprecated signatures (SHA-1, MD5).
- Protocol: the TLS version and cipher negotiated.
- Fingerprints: SHA-1 and SHA-256, plus a crt.sh link to the certificate transparency logs.
How to use
- Enter a domain — add a port for non-HTTPS services (e.g.
mail.example.com:993). - Complete the quick verification and press Check.
- Read the grade, the individual checks, the certificate details and the chain.
Frequently Asked Questions
What does the SSL checker test?
It connects to the host over TLS and reads the certificate: expiry and days left, issuer, Subject Alternative Names, the full chain, key type and size, signature algorithm, the negotiated TLS protocol and cipher, and whether the certificate is trusted and matches the hostname.
Why does it say the chain is incomplete?
The server sent only the leaf certificate without the intermediate CA certificate(s). Desktop browsers often fix this automatically, but many clients don't — install the intermediate chain on your server for full compatibility.
Why is a valid certificate shown as not trusted?
It may be self-signed, issued by a CA that isn't in the public trust store, or missing its intermediate chain. Self-signed certificates are fine internally but browsers won't trust them.
Can I check a non-standard port?
Yes. Add the port after the host, e.g. mail.example.com:993 for IMAPS or example.com:8443. Common secure ports (mail, cPanel, FTPS, LDAPS and more) are supported.
Is my lookup private?
The check runs from our server to the target host using public TLS information. Results are cached briefly for speed and requests are rate-limited; lookups aren't tied to your identity.