Check certificates & TLS configuration
The SSL Checker examines your TLS configuration in detail: certificate chain, supported protocol versions, cipher suites, OCSP stapling and security headers. See at a glance why a certificate is flagged as insecure – and what to do about it.
Guest mode: limited usage. Register for free for unlimited usage, history & statistics.
Register freeStart SSL Analysis
Enter a domain to perform a comprehensive security analysis of its SSL/TLS certificate. Results are cached for 48 hours.
How it works
1. Enter hostname
Enter the domain whose TLS setup you want to check.
2. Start analysis
The checker connects, collecting certificate, ciphers and headers.
3. Read the rating
You get a detailed rating with concrete recommendations.
Features in detail
Protocol support
TLS 1.0 through 1.3, HTTP/2 and HTTP/3 – check what your server really speaks.
Certificate chain
Complete chain analysis including expiry date and intermediate certificates.
Cipher suites
All offered cipher suites with security rating.
OCSP stapling
Check whether OCSP stapling is enabled and working correctly.
DNS CAA & DANE
CAA record and DANE/TLSA configuration checked at the same time.
No account needed
Free and instantly usable without registration.
Frequently asked questions
Why does my browser show the certificate as invalid?
Most common causes: expired certificate, missing intermediate certificates, name mismatch or outdated cipher suites. The SSL Checker shows you exactly which point is the problem.
What is the difference between TLS 1.2 and 1.3?
TLS 1.3 is faster (fewer round trips) and more secure (outdated algorithms removed). Modern servers should offer TLS 1.3.
Is the SSL check free?
Yes, completely free and usable without an account.
Does the checker also test internal certificates?
The checker tests publicly reachable hosts. Internal certificates without a public DNS record cannot be checked.