SSL Certificate Checker
Check any website's SSL certificate and security headers.
Enter a domain without a protocol (e.g. example.com, not https://example.com).
About SSL Certificate Checker.
Check Any Website's SSL Certificate and Security Headers
Enter a domain and CipherForces SSL Checker reports the certificate issuer, expiry date, TLS version, cipher suite, and the full security-header profile (HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy). Identifies weak configurations and gives grade.
Note: Unlike most of our tools, this one necessarily makes a server-side TLS handshake — browsers can't perform TLS-level introspection directly. The request is routed through our /api/ssl-check endpoint with SSRF protection (private IPs and loopback addresses blocked).
Common Use Cases
- Pre-launch audit: Verify your site has valid HTTPS before going live.
- Renewal reminders: Check how many days until your cert expires.
- Vendor security review: Audit a third-party's HTTPS setup before integrating with them.
- Compliance: PCI, SOC 2, and HIPAA require regular TLS audits.
Key Features
- Certificate details: Issuer, subject, validity window, key strength.
- TLS version + cipher suite: Flags deprecated TLS 1.0/1.1 or weak ciphers.
- Security header grade: Scores HSTS, CSP, X-Frame-Options, etc. with remediation guidance.
- Public-only: Only publicly-reachable domains are accepted — no internal networks.
Frequently asked questions.
How do I check a website's SSL certificate?
Type the domain into the SSL Certificate Checker without the protocol, like example.com, then press Check. The tool connects to the site over HTTPS, confirms the certificate works, and reports whether HTTP redirects to HTTPS plus which security headers are present, with a score and fix recommendations.
Is my data uploaded or stored when I run a check?
Only the domain name you enter is sent to our server so it can complete a TLS handshake with that site, which a browser cannot do across origins. No files are uploaded, no account is needed, the tool is free, and no other data about you is stored from the check.
What security headers does the checker test for?
It checks for HSTS (Strict-Transport-Security), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. It also verifies HTTPS works and that HTTP redirects to HTTPS. Each item adds to your score, and missing headers come with specific recommendations on how to add them.
Does a passing score mean my site is fully secure?
No. This certificate checker is informational only and is not a full security audit. It confirms HTTPS works and flags missing security headers, but it does not test your application code, server configuration, or other vulnerabilities. Treat the score as a starting point, not a guarantee.
How to use SSL Certificate Checker.
Enter your input
Type or paste what you want to work with.
Choose settings
Adjust the options for what you need.
Get instant results
Your result updates right on the page.
Related security tools.
Hash Generator
Generate SHA-1, SHA-256, SHA-384, SHA-512 hashes for text and files.
Open toolFile Checksum Verifier
Verify file integrity by comparing SHA-256 checksums.
Open toolEncrypt & Decrypt
Encrypt text and files with AES-256. Decrypt with your password.
Open toolJWT Decoder
Decode a JSON Web Token to inspect its header, payload, and expiry.
Open toolPrivacy-first tools that work everywhere.
Need more than a tool?
One team for your website, print, automation & branding — websites from $799.
Explore all 83 tools