SSL Certificate Checker.
Check a certificate's chain, expiry and hostname match on your website, tracking domain or mail server, with the same handshake real clients make.
AI-powered. AI explains what the results mean and what to fix first; the checker decides every result.
- Expiry And Renew-By Date
- Chain Of Trust
- Hostname, Key And TLS Versions
- STARTTLS, MTA-STS And DANE
- AI Explanation
How it works
A Real Handshake, Then Every Check
The result shows what the server actually sent, not what a browser patched over.
- 01
Enter A Domain, URL Or Email
Pick what it is: a website, a link tracking domain, the mail servers of a domain, or one mail server on port 465, 587, 993 or 25.
- 02
We Connect Like A Client
We open a TLS connection to each address the name resolves to. For mail we speak SMTP, read the capabilities and upgrade with STARTTLS.
- 03
We Check The Chain We Were Sent
Missing intermediates, expired certificates in the chain and the wrong root are caught, because we never fetch a missing certificate on the server's behalf.
- 04
You Get The Fix
Each problem comes with what to change, written for the server software that answered when we can tell which it is.
What we check
Everything A Certificate Problem Can Hide Behind
One run covers the certificate, the server and, for mail, the policies around it.
Certificate And Expiry
The expiry date, the days left and a renew-by date set at a third of the certificate's life, as Let's Encrypt recommends.
- Issuer, names and validation type
- Key and signature against CA rules
- Lifetime against the CA/Browser Forum limit
Chain And Hostname
Whether the chain the server sent reaches a trusted root, and whether the name you typed is covered, wildcards included.
- Missing and expired intermediates
- Self-signed and private roots
- Every IPv4 and IPv6 address
TLS And HTTPS
Which TLS versions the server accepts, and how the site moves visitors to HTTPS and keeps them there.
- TLS 1.0 to 1.3
- HTTP to HTTPS redirect and HSTS
- CAA, revocation and Certificate Transparency
Mail Server TLS
STARTTLS on every MX host, checked against the MX name, and the policies that tell other servers to insist on it.
- STARTTLS and certificates on port 25
- MTA-STS and TLS-RPT
- DANE TLSA records
AI-powered
Plain-English Answers, Checked Against The Result
The checker decides every result. SpirenAI, SendCanyon's AI, only explains what it found and puts the fixes in order. Anything it says that the result cannot back is dropped.
- Explains each problem in plain words
- Says what it means for your site, links or mail
- Orders the fixes, most important first
- Never calls anything fine that was not checked
SSL Checker Questions
What the checker tests, how to read it and how to fix what it finds.
An SSL checker connects to a server the way a browser or mail server would and reports the certificate it presents and whether a client will trust it. This one shows the chain the server actually sent, the expiry and renew-by dates, whether the name you typed is covered, the key and signature, which TLS versions the server accepts, and HSTS, CAA and revocation status. For mail domains it also tests STARTTLS on every MX host.
Send From Domains That Check Out.
SendCanyon checks SPF, DKIM and DMARC on every sending domain before anything sends, and warms new mailboxes on a real ramp.
14-day free trial. No card required.
