Certificate diagnostics

SSL Certificate Expiry Checker

Check the live certificate served by an HTTPS endpoint from multiple regions. See the earliest expiry, hostname coverage, trust result, TLS details, and whether every edge serves the same certificate.

Paste a public hostname or HTTPS URL. Paths are ignored because a TLS certificate is selected before the HTTP request.

Public HTTPS endpoints only. Credentials and local/private addresses are rejected.

For hostnames, choose which address family probes use. An IP literal must match this choice.

Enter a public hostname and select Check certificate. No measurement runs until you press the button.

How to read an SSL expiry result

A valid date alone does not mean a certificate is usable.

Which expiry date should I use?

Use the earliest expiry observed. CDNs and load balancers can serve different certificates by location or IP. A single forgotten edge can fail before the certificate seen by most visitors.

Expiry, trust, and hostname are different checks
  • Expiry asks whether the current time is inside the certificate validity window.
  • Probe authorization reports whether the probe accepted the presented certificate as trusted.
  • Hostname coverage independently compares the requested host with DNS/IP Subject Alternative Names.

A certificate can be unexpired yet fail trust or name validation.

Why might fingerprints differ by region?

Different certificates can be intentional during a rotation, on separate CDN edge fleets, or across IPv4 and IPv6. Compare their expiry, identity and trust state. Investigate any old or failing variant before assuming rollout is complete.

What this checker cannot prove

This is a live leaf-certificate observation, not a complete PKI audit. It does not independently rebuild every chain, query revocation services, search Certificate Transparency logs, prove private-key control, or provide continuous monitoring. The authorization value is the remote probe's TLS-client decision at check time.

Practical renewal checklist
  • Renew before the earliest observed edge reaches your warning threshold.
  • Deploy the full chain to every load balancer, CDN, and IPv4/IPv6 listener.
  • Recheck globally and confirm old fingerprints disappear as intended.
  • Keep automated monitoring outside this page; downloaded calendar dates are reminders, not monitoring.

Live checks use Globalping probes. The queried public hostname, port, and measurement results are sent to Globalping; measurement results are typically available there for up to seven days. Unauthenticated use is subject to its shared IP allowance (currently 250 tests per hour, with each probe counting as one test). Octetify does not claim private, local, SMTP STARTTLS, OCSP, or continuous-monitoring coverage here.