Bulk SSL Certificate Checker
An expired certificate takes a site offline for every modern browser, and the fix is always the same: know the expiry date in advance. This bulk checker connects to port 443 of every domain in your list, in parallel, and reads the certificate presented during the TLS handshake — exactly the way browsers and crawlers see it, because SNI is set to the checked domain and the connection goes to the live resolved IP. The report shows the certificate subject (CN), the issuer, whether the hostname matches the certificate (wildcards included), the expiry date, the number of days left, and an overall validity flag that combines the date window with the hostname match. Certificates that are expired, not yet valid, or issued for a different hostname are marked accordingly, so misconfigured SANs and forgotten renewals surface weeks before they cause incidents. Paste up to one hundred domains, watch the report build live and export it to CSV for your renewal calendar.
How it works
- Paste up to 100 items, one per line. Duplicates are removed automatically.
- If a line contains a full URL, only its host name is used.
- The check runs in the background; the results page shows live progress.
- Filter the report by status code and export it to CSV.
Rate limit: 5 jobs per hour from one IP address. Results are stored for 7 days.
FAQ
When should I renew a certificate?
Most public certificate authorities issue for 90 days. A healthy practice is to renew when "Days left" drops below 30, and to treat anything under 14 as urgent — automated renewals happen days before expiry for a reason.
Why does the hostname not match?
The domain is absent from the certificate's Subject Alternative Names (and the CN does not cover it either). This happens when a certificate was issued for a different domain, a subdomain is not covered by the wildcard, or the server presents the default certificate of the hosting panel.
Does a wildcard certificate cover subdomains?
*.example.com covers one label: a.example.com matches, but a.b.example.com does not, and example.com itself does not either — the naked domain needs its own SAN entry.
What does a TLS error mean?
The TLS handshake itself failed: port 443 is closed, the server speaks only outdated protocol versions, or a firewall drops the connection. No certificate is shown because none was presented. Connection errors (refused, unreachable) are reported separately from TLS errors.