SSL Certificate Checker
Check a domain's SSL certificate the way a browser sees it: when it expires, which names it covers, who issued it, whether the chain is complete, and which TLS versions the server still accepts.
WE1 · Google Trust Services
Checked directly from the ipku.in server: one TLS connection for the certificate, plus one per TLS version. The chain is judged against Mozilla's root CA list. A warning shows 14 days before expiry.
- ✓ValidityValid for 77 more days.
- ✓Domain nameThe certificate covers jetorbit.com.
- ✓Certificate chainComplete and trusted, up to the GTS Root R4 root.
- !TLS versionsAccepts TLS 1.3, TLS 1.2, TLS 1.1, TLS 1.0. TLS 1.0 and 1.1 are obsolete and refused by modern browsers, so they should be turned off.
- name
- jetorbit.com
- SAN (2)
- jetorbit.com*.jetorbit.com
- issuer
- WE1 · Google Trust Services
- valid from
- Sep 17, 2026
- valid until
- Dec 16, 2026
- serial
- 58FDB9BDE66C053E0E15A028C8C62435
- sha-256
- 00:D1:46:D3:5A:8C:64:A4:62:5D:8D:82:DF:6E:D9:3A:D0:4E:58:B7:09:FF:FB:DB:E3:4E:1D:67:F5:AC:9B:1A
- ●jetorbit.comcertificate · valid until Dec 16, 2026
- └WE1intermediate · valid until Feb 20, 2029
- └GTS Root R4intermediate · valid until Jan 28, 2028
- protocol
- TLS 1.3
- cipher
- TLS_AES_128_GCM_SHA256
- alpn
- h2
- TLS 1.3accepted
- TLS 1.2accepted
- TLS 1.1accepted
- TLS 1.0accepted
SSL certificates, briefly.
What is an SSL certificate?
▼
An SSL (strictly, TLS) certificate proves that the server really belongs to the domain and encrypts the connection between browser and server. Without a valid one, browsers show a "Not secure" warning and visitors may leave.
Why does the browser say "not secure" when SSL is installed?
▼
The usual causes: the certificate has expired, it doesn't cover the name being opened (say, example.com but not www.example.com), the intermediate chain isn't installed, or the page loads images and scripts over http:// (mixed content). The first three show up in this check.
What does an incomplete chain mean?
▼
CAs issue certificates through an intermediate certificate, and the server has to send that intermediate along with the domain certificate. Desktop browsers can sometimes fill the gap themselves, but Android, curl, and many apps cannot, and refuse the connection. The fix is to install the CA bundle from the issuer together with the certificate.
How long is a Let’s Encrypt certificate valid?
▼
Let's Encrypt certificates are valid for 90 days and usually renew automatically about 30 days before they run out. If this check shows 14 days or fewer left, automatic renewal has probably failed, for example because the domain's DNS no longer points at the server.
Can I check ports other than 443?
▼
Yes. Pick the port next to the domain field: 465 (SMTPS), 993 (IMAPS), and 995 (POP3S) for mail servers, or 2083, 2087, and 2096 for cPanel, WHM, and webmail. Ports that use STARTTLS, like 25 and 587, are not supported yet.
Can I use it from a terminal?
▼
Yes. curl 'ipku.in/en/tools/ssl-check?q=example.com' returns the check as plain text, and /api/ssl/example.com returns JSON. Add &port=993 or ?port=993 for another port.