Certificate diagnostics
SSL Certificate Expiry Checker
Check the live certificate served by an HTTPS endpoint from multiple regions. See the earliest expiry, hostname coverage, trust result, TLS details, and whether every edge serves the same certificate.
Certificate check results
Certificate observed
Findings and next actions
Expiry, identity, trust and edge consistency are evaluated separately.
Earliest-expiring certificate
The earliest observed edge is the safe renewal date to plan against.
Certificate variants
Different fingerprints can be normal during rotation, but every edge needs a valid certificate.
Probe-by-probe evidence
Select a column heading to sort. Expand Evidence for the exact returned facts.
| Evidence |
|---|
How to read an SSL expiry result
A valid date alone does not mean a certificate is usable.
Which expiry date should I use?
Use the earliest expiry observed. CDNs and load balancers can serve different certificates by location or IP. A single forgotten edge can fail before the certificate seen by most visitors.
Expiry, trust, and hostname are different checks
- Expiry asks whether the current time is inside the certificate validity window.
- Probe authorization reports whether the probe accepted the presented certificate as trusted.
- Hostname coverage independently compares the requested host with DNS/IP Subject Alternative Names.
A certificate can be unexpired yet fail trust or name validation.
Why might fingerprints differ by region?
Different certificates can be intentional during a rotation, on separate CDN edge fleets, or across IPv4 and IPv6. Compare their expiry, identity and trust state. Investigate any old or failing variant before assuming rollout is complete.
What this checker cannot prove
This is a live leaf-certificate observation, not a complete PKI audit. It does not independently rebuild every chain, query revocation services, search Certificate Transparency logs, prove private-key control, or provide continuous monitoring. The authorization value is the remote probe's TLS-client decision at check time.
Practical renewal checklist
- Renew before the earliest observed edge reaches your warning threshold.
- Deploy the full chain to every load balancer, CDN, and IPv4/IPv6 listener.
- Recheck globally and confirm old fingerprints disappear as intended.
- Keep automated monitoring outside this page; downloaded calendar dates are reminders, not monitoring.
Live checks use Globalping probes. The queried public hostname, port, and measurement results are sent to Globalping; measurement results are typically available there for up to seven days. Unauthenticated use is subject to its shared IP allowance (currently 250 tests per hour, with each probe counting as one test). Octetify does not claim private, local, SMTP STARTTLS, OCSP, or continuous-monitoring coverage here.