Tools

SSL certificate and domain expiry check

Enter a website address to see when its certificate and domain registration run out, and whether browsers trust the certificate right now.

You can paste a full link, we will take the domain from it. A check takes up to 15 seconds.

(02) — Details

Why a certificate can take a website down

An SSL certificate proves to the browser that it is talking to your website and not an impostor. Certificates have an expiry date. Once it passes, browsers replace the site with a full-screen “Your connection is not private” warning. Few visitors click through, and forms, payments and CRM integrations stop working.

Lifetimes are getting shorter. Let's Encrypt issues 90-day certificates. Under rules agreed by browsers and certificate authorities, the maximum lifetime of any public certificate is 200 days from March 2026, 100 days from March 2027 and 47 days from March 2029. Renewing by hand once a year no longer works: you need auto-renewal and a way to know it actually runs.

Domain expiry and the grace period

Domains are registered for one or more years in advance. The expiry date comes from the registry. In the Russian zones .ru, .рф and .su the registry publishes two dates: paid-till, when the domain stops working, and free-date, the last day only the current owner can renew it, roughly a month later. After that, anyone can register the domain, including drop-catchers who watch for expiring names.

In international zones (.com, .net, .org) there is usually a renewal grace period too, but its length depends on the registrar, and the website may stop working on the very first day.

How not to miss a renewal

  • Turn on domain auto-renewal at your registrar and make sure the linked card is valid for longer than the domain.
  • Keep the domain owner's email working: registrars send reminders there.
  • For Let's Encrypt, make sure auto-renewal is set up on the server: certbot, acme.sh or the one built into the hosting panel. Paid certificates are renewed where you bought them, and the new one still has to be installed on the server.
  • Check the dates on this page once a month, or hand it to whoever maintains your website.
(03) — Questions

Questions.

How often should I check certificate and domain expiry?
With auto-renewal in place, once a month. If the certificate or domain is renewed by hand, set reminders 30 days before expiry and another one a week before.
What happens when a certificate expires?
Browsers show a warning instead of the website. Forms, payments and anything that talks to the site over HTTPS stop working: payment notifications, CRM webhooks, mobile apps.
We renewed the certificate, but the old date still shows. Why?
Results are kept for 5 minutes, so wait and check again. If the date still has not changed, the new certificate was issued but the web server has not picked it up: it needs a restart or a configuration fix.
Why is the domain expiry date missing?
Some registries do not publish it, for example .de and .kz. The same goes for third-level names such as site.spb.ru. In those cases only your registrar account shows the date.
Can I check a subdomain?
Yes. The certificate is checked for the exact address you enter, for example shop.example.com, and the registration for the main domain, example.com.
What is an intermediate certificate?
The link between your site's certificate and the root certificate that browsers trust. The server must send it together with the site certificate. If it does not, desktop Chrome often rebuilds the chain itself, while phones, older browsers and integrations report an error.
(04) — Studio

Rather not track expiry dates by hand?

Certificate and domain monitoring is part of our website support: we watch the dates, renew ahead of time and hear about problems before your visitors do.