An expired certificate is one of the most avoidable outages a website can have. The day it lapses, browsers show a full-page warning and most visitors leave. Knowing how to check SSL certificate expiry takes less than a minute, and building a habit around it means the warning never appears in the first place.
Why certificates expire at all
An SSL/TLS certificate is a signed statement from a certificate authority (CA) saying "this public key belongs to this domain". Every certificate carries two dates: Not Before and Not After. Once the Not After date passes, browsers treat the certificate as invalid, even if nothing else has changed.
Short lifetimes are deliberate. If a private key is stolen or a domain changes hands, a short-lived certificate limits how long the old one can be misused. The CA/Browser Forum, the industry body that sets the rules for publicly trusted certificates, has agreed to reduce maximum lifetimes in stages over the coming years, so renewals will become more frequent, not less. Free CAs such as Let's Encrypt already issue 90-day certificates. The practical lesson is that manual, once-a-year renewal is on its way out.
Method 1: Check in your browser
This is the quickest check for a single site:
- Open the site over
https://. - Click the padlock or site-information icon to the left of the address.
- Choose the option for connection security, then "Certificate is valid" (Chrome and Edge) or "More information" and "View certificate" (Firefox).
- Look for the Validity section and the Expires On or Not After date.
The limitation is that you only see the certificate served to your connection. If the site sits behind several load-balanced servers, one of them may still have an older certificate.
Method 2: Use an online SSL checker
An online checker connects to the server the same way a browser does and reports the expiry date, the number of days remaining, the issuer, the names covered, and whether the chain of intermediate certificates is complete. Our free SSL checker does exactly this and also flags problems such as a name mismatch, which often surface at renewal time when someone forgets to include a subdomain.
This is the most useful method for non-technical staff, and it works for any public site, not just your own.
Method 3: Check SSL certificate expiry with OpenSSL
On Linux, macOS or Windows with Git Bash, OpenSSL lets you script the check. To print the expiry date of a live site:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -enddate
The output looks like notAfter=Jan 14 23:59:59 2027 GMT. The -servername flag matters: it sends Server Name Indication (SNI), which tells a server hosting many sites which certificate to return. Without it you may see the wrong certificate.
To test whether a certificate expires within the next 30 days (2,592,000 seconds), use -checkend:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -checkend 2592000
It prints "Certificate will not expire" and exits with code 0, or "Certificate will expire" with exit code 1, which makes it easy to use in a cron job or monitoring script.
If you have the certificate as a file on the server, skip the network part:
openssl x509 -in /etc/ssl/certs/example.com.crt -noout -dates
Method 4: Check from PowerShell on Windows
Windows admins can read certificates in the local machine store directly:
Get-ChildItem Cert:\LocalMachine\My |
Select-Object Subject, NotAfter |
Sort-Object NotAfter
This lists every certificate in the computer's personal store, with the soonest to expire at the top, which is handy on IIS servers hosting several sites. To find anything expiring within 30 days:
Get-ChildItem Cert:\LocalMachine\My |
Where-Object { $_.NotAfter -lt (Get-Date).AddDays(30) }
Do not forget the certificates you cannot see
Website certificates are the obvious ones. Others expire just as reliably and are easier to overlook:
- Mail servers using TLS on ports 465, 587 or 993. Check them with
openssl s_client -connect mail.example.com:993, or for port 587 add-starttls smtp. - Internal tools such as admin panels, VPN gateways and printers with web interfaces.
- API endpoints and webhooks that partners call. A lapsed certificate here breaks integrations silently rather than showing a browser warning.
- Load balancers and CDNs, which may hold their own copy of the certificate separate from your origin server.
Prevent expiry instead of reacting to it
Checking is a safety net; automation is the real fix.
- Automate renewal wherever possible. ACME clients such as Certbot renew Let's Encrypt and other ACME-compatible certificates automatically. Many hosting panels and cloud load balancers renew managed certificates for you.
- Test the renewal path, not just the certificate. With Certbot,
sudo certbot renew --dry-runconfirms renewal would succeed. Renewals often fail because a firewall change blocked port 80 or a DNS record moved. - Monitor independently. Use an external check that alerts at 30, 14 and 7 days remaining. Automated renewal can break quietly; monitoring tells you before visitors do.
- Keep an inventory. A simple spreadsheet listing each certificate, where it is installed, who owns it and how it renews is enough for most small businesses. Review it as part of routine server management.
- Use a shared mailbox for CA expiry notices, not one employee's personal address.
Key takeaways
- Every certificate has a hard Not After date; browsers reject it the moment that passes.
- Use the browser for a quick look, an online checker for a full picture, and OpenSSL or PowerShell for scripts.
- Always include SNI (
-servername) when checking with OpenSSL. - Certificate lifetimes are getting shorter, so automate renewal and monitor expiry separately.