Skip to content
ForgePlug — Logo
developerRuns Server-SideNo Signup

SSL Checker

A real SSL/TLS checker that opens an actual TLS handshake on port 443 and reads the live certificate chain — no cached or approximate data. See the exact expiry date and days remaining, the issuing CA, whether the chain is complete, the negotiated protocol version (flagging deprecated TLS 1.0/1.1), and the cipher suite (flagging known-weak ciphers). Part of ForgePlug's Site Health Check, which also runs DNS, HTTP security header, and robots.txt checks on the same domain at no extra cost.

This check runs server-side — ForgePlug briefly connects to the domain you enter to read its certificate, DNS records, response headers, and robots.txt/sitemap. We don't store anything beyond a 5-minute result cache (to avoid re-running the same check for everyone hitting a trending domain) and a short-lived snapshot used to compare a re-check later.

How this SSL checker reads your certificate

A real TLS handshake on port 443, not a cached lookup.

Most "SSL checker" pages either scrape a third-party certificate transparency log or reuse a stale cached result. This one opens an actual TLS connection to your domain on port 443 and reads the certificate the server presents right now — the same handshake a visitor's browser performs.

From that handshake it reports the exact expiry date and days remaining, the issuing certificate authority, whether the full chain (leaf → intermediate → root) resolves to a trusted authority, which protocol version was negotiated — flagging TLS 1.0 and 1.1, which modern browsers are actively deprecating — and the negotiated cipher suite, flagging known-weak ciphers like RC4 or 3DES.

Because it's part of ForgePlug's full Site Health Check, submitting also runs a DNS propagation check, an HTTP security header scan, and a robots.txt/sitemap validation on the same domain — all in parallel, at no extra cost.

Frequently Asked Questions

SSL certificate checking, explained

How is this different from a dedicated SSL checker?
It performs the same real TLS handshake on port 443 that a dedicated SSL checker does — reading the certificate chain, expiry, negotiated protocol version, and cipher suite — and flags TLS 1.0/1.1 and known-weak ciphers. It also runs the DNS, header, and robots.txt checks alongside it at no extra cost, since they're already part of the same tool.
What counts as an expiring certificate?
This tool warns at 21 days remaining and fails once a certificate has actually expired. Renewing with a couple of weeks of headroom avoids the last-minute scramble if a renewal job silently fails.
Is this really free, and is there a limit?
Yes — Site Health Check is free and doesn't require an account. Like every ForgePlug tool it's rate-limited per IP address (a handful of checks per minute) to keep the service fast and available for everyone, not to push a paid tier.
Why does this tool need a server? Aren't ForgePlug's tools all browser-based?
Almost all of them are — but a browser can't open a raw TLS handshake, query a DNS resolver directly, or fetch another site's headers without hitting CORS. Those three things require a real network connection from a server, so this one tool runs a small, rate-limited check server-side instead of pretending it can do it client-side.
What do you do with the domain I check?
The check result is cached for 5 minutes so a burst of people checking the same trending domain doesn't trigger five fresh outbound connections each time, and the most recent result is kept briefly so a re-check can eventually show what changed. We don't log who checked what.
Can I check an internal or private server?
No — the tool refuses any hostname that resolves to a private, loopback, or link-local address (including cloud metadata endpoints) as a security precaution. Enter a public domain name, not an internal hostname or a bare IP address.
What does the overall pass/warn/fail badge mean?
It's the worst result across all four panels, not an average: two or more failing panels caps the overall badge at fail, one failing panel caps it at warn, and any warning (with no failures) also shows as warn. A clean pass means all four checks came back clean.

Guides & Articles

Learn how to get the most out of this tool with our in-depth guides.

Was this tool helpful?

Your feedback helps us improve SSL Checker for everyone.

Share this tool

Share