Skip to content
Comfort

SSL certificate check

We will show who the certificate is issued to, who signed it, and how many days it has left. Every detected issue is explained in plain language.

For example, gosuslugi.ru or www.example.com

For example:

What the check shows

We connect to the site just like a browser does and parse the certificate it presents: which names it is issued for, who signed it, and its validity dates. You can also see the protocol version and cipher to know how modern the connection setup is.

Why tracking expiration dates matters

Certificates are issued for a limited period — most often 90 days or a year. When it expires, browsers display a warning page, and most visitors leave. Renewal is usually automated, but automated systems can fail too.

In your personal account, you can add your site to monitoring: we check it every 5 minutes and will email you 14, 7, 3, and 1 day before the certificate expires.

Russian certificates: why browsers complain

Some Russian websites — banks, government services — have switched to certificates from the National Certification Authority of the Ministry of Digital Development. Its root certificate is built into Yandex Browser, but needs to be installed manually in Chrome, Firefox, and Safari. Without it, the browser warns of an insecure connection even though the site is authentic.

How to inspect a certificate yourself

In any browser, click the icon to the left of the address bar and view the connection or certificate details. You will see the same fields as here: issued to, issued by, and expiration date.

FAQ

The certificate is active, but the browser still warns. Why?

Most often, the server does not send the intermediate certificate, the certificate was issued for a different name, or it was issued by a Russian certificate authority unfamiliar to the browser. The check highlights each of these cases.

What are Subject Alternative Names (SAN)?

A list of addresses covered by the certificate. A single certificate can protect example.com, www.example.com, and all subdomains at once via a wildcard.

What TLS version is considered acceptable?

TLS 1.3 and 1.2. Versions 1.0 and 1.1 are obsolete, and modern browsers no longer support them.

Is a free certificate worse than a paid one?

For encryption, no — it provides the exact same protection. Paid certificates differ in business identity verification and validity duration, not in connection security.