Godwit AI Labs Talk to us

Home › Free tools › Certificate check

Will your certificate lapse without warning?

Certificates are getting shorter: 200 days now, 100 from March 2027, 47 by 2029. Check when yours expires, whether renewal looks automated, and whether the connection, HSTS and CAA records are set up properly.

  • A few seconds
  • Reads only what any browser sees
  • Stores nothing about the check
QUESTIONS

Asked often

The questions people search for before they run the check.

How long can an SSL certificate last now?

Public TLS certificates issued from 15 March 2026 can be valid for at most 200 days. The limit falls to 100 days from 15 March 2027 and to 47 days from 15 March 2029, under the CA/Browser Forum's Ballot SC-081. Renewing by hand stops being workable.

How do I check when my SSL certificate expires?

Type the site's name above. The check connects to it the way a browser does and reads the certificate's expiry date, who issued it, whether it covers the name, and whether the chain is complete. In a browser you can also click the padlock and view the certificate.

How do I automate certificate renewal?

Use ACME, the protocol behind Let's Encrypt, which most certificate authorities, web servers and hosting panels support. A small client renews each certificate before it expires. Add an alert for failed renewals, because a renewal that quietly stops is how certificates still lapse.

What is a CAA record?

A DNS record that names the certificate authorities allowed to issue certificates for your domain. Without one, any public authority could issue a certificate for it if tricked. Adding one is a single DNS entry, such as 0 issue "letsencrypt.org".

Is it safe to check my site here?

The check makes one ordinary https connection to the site, reads the certificate and the HSTS header, and looks up public DNS records: what any browser sees. It stores nothing about the check, and only reaches public addresses on port 443.

The site is one certificate of many

Mail, VPN, firewalls, load balancers and internal portals all carry certificates, and the ones nobody remembers are the ones that lapse. We find them all and put each on automatic renewal.