Check certificates & TLS configuration

The SSL Checker examines your TLS configuration in detail: certificate chain, supported protocol versions, cipher suites, OCSP stapling and security headers. See at a glance why a certificate is flagged as insecure – and what to do about it.

FreeAccount requiredResults in seconds

Guest mode: limited usage. Register for free for unlimited usage, history & statistics.

Register free

Start SSL Analysis

Enter a domain to perform a comprehensive security analysis of its SSL/TLS certificate. Results are cached for 48 hours.

How it works

1

1. Enter hostname

Enter the domain whose TLS setup you want to check.

2

2. Start analysis

The checker connects, collecting certificate, ciphers and headers.

3

3. Read the rating

You get a detailed rating with concrete recommendations.

Features in detail

Protocol support

TLS 1.0 through 1.3, HTTP/2 and HTTP/3 – check what your server really speaks.

Certificate chain

Complete chain analysis including expiry date and intermediate certificates.

Cipher suites

All offered cipher suites with security rating.

OCSP stapling

Check whether OCSP stapling is enabled and working correctly.

DNS CAA & DANE

CAA record and DANE/TLSA configuration checked at the same time.

No account needed

Free and instantly usable without registration.

Frequently asked questions

Why does my browser show the certificate as invalid?

Most common causes: expired certificate, missing intermediate certificates, name mismatch or outdated cipher suites. The SSL Checker shows you exactly which point is the problem.

What is the difference between TLS 1.2 and 1.3?

TLS 1.3 is faster (fewer round trips) and more secure (outdated algorithms removed). Modern servers should offer TLS 1.3.

Is the SSL check free?

Yes, completely free and usable without an account.

Does the checker also test internal certificates?

The checker tests publicly reachable hosts. Internal certificates without a public DNS record cannot be checked.

Related guides