An SSL Labs alternative for the question you actually have

SSL Labs is the most thorough TLS audit available to anyone, free, and nothing here competes with it. It also takes minutes to run, tests a great deal you did not ask about, and adds your result to a public list unless you remember the checkbox. Most of the time the question is simply when does this expire.

Open the SSL Checker →

SSL Labs and Softland, side by side

 SSL LabsSoftland
Expiry, issuer and covered hostnamesIncluded in a full reportThe whole report
Chain completenessChecked thoroughlyChecked
Protocol versions and cipher suitesExhaustive, with a gradeNot assessed
How long it takesMinutesSeconds
Results publishedListed publicly unless you opt outNot listed anywhere

The incomplete chain, and why it only breaks for some people

A server must send its own certificate plus the intermediates that connect it to a trusted root. When it sends only its own, some clients still work - because they happen to have cached the intermediate from another site - and others fail completely. The result is a site that works in your browser, works for most of the office, and is untrusted on a colleague phone or on a server making an API call.

This is the most common TLS misconfiguration and the hardest to diagnose from the inside, precisely because the person checking is usually one of the people for whom it works. A checker fetching the chain from outside sees what is actually being sent rather than what your browser has assembled from its own cache.

Expiry is a calendar problem disguised as a technical one

Certificates expire, automated renewal fails silently, and the failure surfaces as a total outage with a frightening browser warning rather than as a degraded service. Nothing about it is subtle: at the expiry moment the site simply stops being usable for everyone at once, and the people best placed to notice early are asleep.

The defence is knowing the date before it arrives and monitoring the renewal rather than trusting it. Checking by hand answers today question; if the answer matters more than once, an uptime monitor that watches the certificate is the thing that actually prevents the outage.

What the certificate covers is a separate question from whether it is valid

A perfectly valid certificate produces a browser warning if the name does not match. Wildcards are the usual cause of confusion: a wildcard covers one level of subdomain and no more, so it secures the direct children of a domain and not their children in turn. A certificate for the bare domain does not automatically cover the www version, and vice versa, unless both are listed.

So when a site is trusted on one hostname and warns on another, the certificate is usually fine and the list of names on it is the problem. Reading that list settles it immediately, and it is the second question after expiry rather than a separate investigation.

When SSL Labs is the better choice

  • You need a real security assessment - protocol versions, cipher suite ordering, known vulnerabilities, forward secrecy - which this does not attempt.
  • You want a grade to put in front of a customer, an auditor or a procurement questionnaire.
  • You are hardening a server configuration and need to see exactly which clients would still connect.

Frequently asked questions

How do I check when a certificate expires?
Enter the hostname. The expiry date is read from the certificate the server presents, along with who issued it and which names it covers.
What happens when a certificate expires?
Browsers show a full-page warning and most refuse to continue without an explicit click. API clients and anything automated usually fail outright with no warning at all, which is often how it is discovered.
What is an incomplete certificate chain?
The server is sending its own certificate but not the intermediates linking it to a trusted root. Clients that have the intermediate cached still work, which is why it appears to work for some people and not others.
Does a wildcard certificate cover every subdomain?
Only one level. It covers the direct children of the domain, not the children of those. Deeper names need their own certificate or their own wildcard.

Try it yourself

Check a certificate and when it expires.

Open the SSL Checker

SSL Labs is a trademark of its respective owner. Softland is not affiliated with, endorsed by or sponsored by SSL Labs. This comparison reflects how each product works rather than what either costs, because pricing and plan limits change; check SSL Labs’s own site for its current terms.