SendCanyon

SSL Certificate Checker.

Check a certificate's chain, expiry and hostname match on your website, tracking domain or mail server, with the same handshake real clients make.

AI-powered. AI explains what the results mean and what to fix first; the checker decides every result.

What To Check
More Options
  • Expiry And Renew-By Date
  • Chain Of Trust
  • Hostname, Key And TLS Versions
  • STARTTLS, MTA-STS And DANE
  • AI Explanation

How it works

A Real Handshake, Then Every Check

The result shows what the server actually sent, not what a browser patched over.

  1. 01

    Enter A Domain, URL Or Email

    Pick what it is: a website, a link tracking domain, the mail servers of a domain, or one mail server on port 465, 587, 993 or 25.

  2. 02

    We Connect Like A Client

    We open a TLS connection to each address the name resolves to. For mail we speak SMTP, read the capabilities and upgrade with STARTTLS.

  3. 03

    We Check The Chain We Were Sent

    Missing intermediates, expired certificates in the chain and the wrong root are caught, because we never fetch a missing certificate on the server's behalf.

  4. 04

    You Get The Fix

    Each problem comes with what to change, written for the server software that answered when we can tell which it is.

What we check

Everything A Certificate Problem Can Hide Behind

One run covers the certificate, the server and, for mail, the policies around it.

  • Certificate And Expiry

    The expiry date, the days left and a renew-by date set at a third of the certificate's life, as Let's Encrypt recommends.

    • Issuer, names and validation type
    • Key and signature against CA rules
    • Lifetime against the CA/Browser Forum limit
  • Chain And Hostname

    Whether the chain the server sent reaches a trusted root, and whether the name you typed is covered, wildcards included.

    • Missing and expired intermediates
    • Self-signed and private roots
    • Every IPv4 and IPv6 address
  • TLS And HTTPS

    Which TLS versions the server accepts, and how the site moves visitors to HTTPS and keeps them there.

    • TLS 1.0 to 1.3
    • HTTP to HTTPS redirect and HSTS
    • CAA, revocation and Certificate Transparency
  • Mail Server TLS

    STARTTLS on every MX host, checked against the MX name, and the policies that tell other servers to insist on it.

    • STARTTLS and certificates on port 25
    • MTA-STS and TLS-RPT
    • DANE TLSA records

AI-powered

Plain-English Answers, Checked Against The Result

The checker decides every result. SpirenAI, SendCanyon's AI, only explains what it found and puts the fixes in order. Anything it says that the result cannot back is dropped.

  • Explains each problem in plain words
  • Says what it means for your site, links or mail
  • Orders the fixes, most important first
  • Never calls anything fine that was not checked

SSL Checker Questions

What the checker tests, how to read it and how to fix what it finds.

An SSL checker connects to a server the way a browser or mail server would and reports the certificate it presents and whether a client will trust it. This one shows the chain the server actually sent, the expiry and renew-by dates, whether the name you typed is covered, the key and signature, which TLS versions the server accepts, and HSTS, CAA and revocation status. For mail domains it also tests STARTTLS on every MX host.

Send From Domains That Check Out.

SendCanyon checks SPF, DKIM and DMARC on every sending domain before anything sends, and warms new mailboxes on a real ramp.

Start free trialBook a demo

14-day free trial. No card required.

Free SSL Checker: Certificate, Chain and Expiry | SendCanyon