Certificates are getting shorter: 200 days now, 100 from March 2027, 47 by 2029. Check when yours expires, whether renewal looks automated, and whether the connection, HSTS and CAA records are set up properly.
A few seconds
Reads only what any browser sees
Stores nothing about the check
Example report
www.shop.example
19 days left
Renewed by hand, once a yearFix
Still accepts TLS 1.0Next
No CAA recordNext
More in the full report●●●
Connecting to the site on port 443
Reading the certificate and its chain
Checking the protocol, HSTS and CAA
Working out the report in your browser
Certificate report
1 Summary
Renewals a year, per certificate
2 The checks
3 What this could not check
One handshake with the site named, from our server in India, on the date shown. Whether renewal is automated is judged from the issuer and the certificate’s lifetime: a strong clue, not proof. Lifetimes from CA/Browser Forum Ballot SC-081v3. Guidance, not an audit; see the terms.
QUESTIONS
Asked often
The questions people search for before they run the check.
How long can an SSL certificate last now?
Public TLS certificates issued from 15 March 2026 can be valid for at most 200 days. The limit falls to 100 days from 15 March 2027 and to 47 days from 15 March 2029, under the CA/Browser Forum's Ballot SC-081. Renewing by hand stops being workable.
How do I check when my SSL certificate expires?
Type the site's name above. The check connects to it the way a browser does and reads the certificate's expiry date, who issued it, whether it covers the name, and whether the chain is complete. In a browser you can also click the padlock and view the certificate.
How do I automate certificate renewal?
Use ACME, the protocol behind Let's Encrypt, which most certificate authorities, web servers and hosting panels support. A small client renews each certificate before it expires. Add an alert for failed renewals, because a renewal that quietly stops is how certificates still lapse.
What is a CAA record?
A DNS record that names the certificate authorities allowed to issue certificates for your domain. Without one, any public authority could issue a certificate for it if tricked. Adding one is a single DNS entry, such as 0 issue "letsencrypt.org".
Is it safe to check my site here?
The check makes one ordinary https connection to the site, reads the certificate and the HSTS header, and looks up public DNS records: what any browser sees. It stores nothing about the check, and only reaches public addresses on port 443.
Godwit AI Labs
This report is available as a branded PDF. Use “Download the report” on the page,
or ask us for the detailed review at godwit-tech.com/contact.
The site is one certificate of many
Mail, VPN, firewalls, load balancers and internal portals all carry certificates, and the ones nobody remembers are the ones that lapse. We find them all and put each on automatic renewal.