ip
ipku.in

SSL Certificate Checker

Check a domain's SSL certificate the way a browser sees it: when it expires, which names it covers, who issued it, whether the chain is complete, and which TLS versions the server still accepts.

Result
Needs attention
64 days leftvalid until Dec 3, 2026
3 pass1 warning

WR2 · Google Trust Services

DNS for this domain →Look up the server IP →Full analysis of this domain →json ↗

Checked directly from the ipku.in server: one TLS connection for the certificate, plus one per TLS version. The chain is judged against Mozilla's root CA list. A warning shows 14 days before expiry.

Checks
  • ✓
    ValidityValid for 64 more days.
  • ✓
    Domain nameThe certificate covers google.com.
  • ✓
    Certificate chainComplete and trusted, up to the GTS Root R1 root.
  • !
    TLS versionsAccepts TLS 1.3, TLS 1.2, TLS 1.1, TLS 1.0. TLS 1.0 and 1.1 are obsolete and refused by modern browsers, so they should be turned off.
CertificateEC P-256
name
*.google.com
SAN (65)
*.google.com*.appengine.google.com*.bdn.dev*.origin-test.bdn.dev*.cloud.google.com*.crowdsource.google.com*.datacompute.google.com*.google.ca*.google.cl*.google.co.in*.google.co.jp*.google.co.uk*.google.com.ar*.google.com.au*.google.com.br*.google.com.co*.google.com.mx*.google.com.tr*.google.com.vn*.google.de*.google.es*.google.fr*.google.hu*.google.it*.google.nl*.google.pl*.google.pt*.gemini.cloud.google.com*.gstatic.com*.metric.gstatic.com*.gvt1.com*.gcpcdn.gvt1.com*.gvt2.com*.gcp.gvt2.com*.url.google.com*.youtube-nocookie.com*.ytimg.comai.androidandroid.com*.android.com*.flash.android.comg.co*.g.cogoo.glwww.goo.glgoogle-analytics.com*.google-analytics.comgoogle.comgooglecommerce.com*.googlecommerce.comurchin.com*.urchin.comyoutu.beyoutube.com*.youtube.commusic.youtube.com*.music.youtube.comyoutubeeducation.com*.youtubeeducation.comyoutubekids.com*.youtubekids.comyt.be*.yt.beandroid.clients.google.com*.aistudio.google.com
issuer
WR2 · Google Trust Services
valid from
Sep 10, 2026
valid until
Dec 3, 2026
serial
44BE0DDE901AE99B0AB29255F94109E5
sha-256
FB:C1:41:B6:11:F1:50:E5:B4:AC:09:1C:7C:4D:28:48:AE:90:06:51:C9:8B:57:A3:5E:14:EC:A8:7C:30:F4:19
Chain3
  1. ●
    *.google.comcertificate · valid until Dec 3, 2026
  2. └
    WR2intermediate · valid until Feb 20, 2029
  3. └
    GTS Root R1intermediate · valid until Jan 28, 2028
Connection:443
protocol
TLS 1.3
cipher
TLS_AES_128_GCM_SHA256
alpn
h2
  • TLS 1.3accepted
  • TLS 1.2accepted
  • TLS 1.1accepted
  • TLS 1.0accepted
01 / faq

SSL certificates, briefly.

What is an SSL certificate?

▼

An SSL (strictly, TLS) certificate proves that the server really belongs to the domain and encrypts the connection between browser and server. Without a valid one, browsers show a "Not secure" warning and visitors may leave.

Why does the browser say "not secure" when SSL is installed?

▼

The usual causes: the certificate has expired, it doesn't cover the name being opened (say, example.com but not www.example.com), the intermediate chain isn't installed, or the page loads images and scripts over http:// (mixed content). The first three show up in this check.

What does an incomplete chain mean?

▼

CAs issue certificates through an intermediate certificate, and the server has to send that intermediate along with the domain certificate. Desktop browsers can sometimes fill the gap themselves, but Android, curl, and many apps cannot, and refuse the connection. The fix is to install the CA bundle from the issuer together with the certificate.

How long is a Let’s Encrypt certificate valid?

▼

Let's Encrypt certificates are valid for 90 days and usually renew automatically about 30 days before they run out. If this check shows 14 days or fewer left, automatic renewal has probably failed, for example because the domain's DNS no longer points at the server.

Can I check ports other than 443?

▼

Yes. Pick the port next to the domain field: 465 (SMTPS), 993 (IMAPS), and 995 (POP3S) for mail servers, or 2083, 2087, and 2096 for cPanel, WHM, and webmail. Ports that use STARTTLS, like 25 and 587, are not supported yet.

Can I use it from a terminal?

▼

Yes. curl 'ipku.in/en/tools/ssl-check?q=example.com' returns the check as plain text, and /api/ssl/example.com returns JSON. Add &port=993 or ?port=993 for another port.