ip
ipku.in

SSL Certificate Checker

Check a domain's SSL certificate the way a browser sees it: when it expires, which names it covers, who issued it, whether the chain is complete, and which TLS versions the server still accepts.

Result
Certificate is valid
83 days leftvalid until Dec 22, 2026
4 pass

Thawte TLS RSA CA G1 · DigiCert Inc

DNS for this domain →Look up the server IP →Full analysis of this domain →json ↗

Checked directly from the ipku.in server: one TLS connection for the certificate, plus one per TLS version. The chain is judged against Mozilla's root CA list. A warning shows 14 days before expiry.

Checks
  • ✓
    ValidityValid for 83 more days.
  • ✓
    Domain nameThe certificate covers detik.com.
  • ✓
    Certificate chainComplete and trusted, up to the DigiCert Global Root G2 root.
  • ✓
    TLS versionsAccepts TLS 1.3, TLS 1.2.
CertificateRSA 2048
name
*.detik.com · PT. Trans Digital Media
SAN (2)
*.detik.comdetik.com
issuer
Thawte TLS RSA CA G1 · DigiCert Inc
valid from
Dec 15, 2025
valid until
Dec 22, 2026
serial
01575A54A7FA6722D29B313E7F7E55DB
sha-256
A8:E2:31:17:F8:0A:33:D9:32:11:2E:B0:64:AA:9D:52:FB:4E:61:74:7D:31:CF:12:84:FC:1F:EF:25:A4:98:28
Chain3
  1. ●
    *.detik.comcertificate · valid until Dec 22, 2026
  2. └
    Thawte TLS RSA CA G1intermediate · valid until Nov 2, 2027
  3. └
    DigiCert Global Root G2root · valid until Jan 15, 2038
Connection:443
protocol
TLS 1.3
cipher
TLS_AES_256_GCM_SHA384
alpn
h2
  • TLS 1.3accepted
  • TLS 1.2accepted
  • TLS 1.1refused
  • TLS 1.0refused
01 / faq

SSL certificates, briefly.

What is an SSL certificate?

▼

An SSL (strictly, TLS) certificate proves that the server really belongs to the domain and encrypts the connection between browser and server. Without a valid one, browsers show a "Not secure" warning and visitors may leave.

Why does the browser say "not secure" when SSL is installed?

▼

The usual causes: the certificate has expired, it doesn't cover the name being opened (say, example.com but not www.example.com), the intermediate chain isn't installed, or the page loads images and scripts over http:// (mixed content). The first three show up in this check.

What does an incomplete chain mean?

▼

CAs issue certificates through an intermediate certificate, and the server has to send that intermediate along with the domain certificate. Desktop browsers can sometimes fill the gap themselves, but Android, curl, and many apps cannot, and refuse the connection. The fix is to install the CA bundle from the issuer together with the certificate.

How long is a Let’s Encrypt certificate valid?

▼

Let's Encrypt certificates are valid for 90 days and usually renew automatically about 30 days before they run out. If this check shows 14 days or fewer left, automatic renewal has probably failed, for example because the domain's DNS no longer points at the server.

Can I check ports other than 443?

▼

Yes. Pick the port next to the domain field: 465 (SMTPS), 993 (IMAPS), and 995 (POP3S) for mail servers, or 2083, 2087, and 2096 for cPanel, WHM, and webmail. Ports that use STARTTLS, like 25 and 587, are not supported yet.

Can I use it from a terminal?

▼

Yes. curl 'ipku.in/en/tools/ssl-check?q=example.com' returns the check as plain text, and /api/ssl/example.com returns JSON. Add &port=993 or ?port=993 for another port.