ip
ipku.in

SSL Certificate Checker

Check a domain's SSL certificate the way a browser sees it: when it expires, which names it covers, who issued it, whether the chain is complete, and which TLS versions the server still accepts.

Result
Needs attention
77 days leftvalid until Dec 16, 2026
3 pass1 warning

WE1 · Google Trust Services

DNS for this domain →Look up the server IP →Full analysis of this domain →json ↗

Checked directly from the ipku.in server: one TLS connection for the certificate, plus one per TLS version. The chain is judged against Mozilla's root CA list. A warning shows 14 days before expiry.

Checks
  • ✓
    ValidityValid for 77 more days.
  • ✓
    Domain nameThe certificate covers jetorbit.com.
  • ✓
    Certificate chainComplete and trusted, up to the GTS Root R4 root.
  • !
    TLS versionsAccepts TLS 1.3, TLS 1.2, TLS 1.1, TLS 1.0. TLS 1.0 and 1.1 are obsolete and refused by modern browsers, so they should be turned off.
CertificateEC P-256
name
jetorbit.com
SAN (2)
jetorbit.com*.jetorbit.com
issuer
WE1 · Google Trust Services
valid from
Sep 17, 2026
valid until
Dec 16, 2026
serial
58FDB9BDE66C053E0E15A028C8C62435
sha-256
00:D1:46:D3:5A:8C:64:A4:62:5D:8D:82:DF:6E:D9:3A:D0:4E:58:B7:09:FF:FB:DB:E3:4E:1D:67:F5:AC:9B:1A
Chain3
  1. ●
    jetorbit.comcertificate · valid until Dec 16, 2026
  2. └
    WE1intermediate · valid until Feb 20, 2029
  3. └
    GTS Root R4intermediate · valid until Jan 28, 2028
Connection:443
protocol
TLS 1.3
cipher
TLS_AES_128_GCM_SHA256
alpn
h2
  • TLS 1.3accepted
  • TLS 1.2accepted
  • TLS 1.1accepted
  • TLS 1.0accepted
01 / faq

SSL certificates, briefly.

What is an SSL certificate?

▼

An SSL (strictly, TLS) certificate proves that the server really belongs to the domain and encrypts the connection between browser and server. Without a valid one, browsers show a "Not secure" warning and visitors may leave.

Why does the browser say "not secure" when SSL is installed?

▼

The usual causes: the certificate has expired, it doesn't cover the name being opened (say, example.com but not www.example.com), the intermediate chain isn't installed, or the page loads images and scripts over http:// (mixed content). The first three show up in this check.

What does an incomplete chain mean?

▼

CAs issue certificates through an intermediate certificate, and the server has to send that intermediate along with the domain certificate. Desktop browsers can sometimes fill the gap themselves, but Android, curl, and many apps cannot, and refuse the connection. The fix is to install the CA bundle from the issuer together with the certificate.

How long is a Let’s Encrypt certificate valid?

▼

Let's Encrypt certificates are valid for 90 days and usually renew automatically about 30 days before they run out. If this check shows 14 days or fewer left, automatic renewal has probably failed, for example because the domain's DNS no longer points at the server.

Can I check ports other than 443?

▼

Yes. Pick the port next to the domain field: 465 (SMTPS), 993 (IMAPS), and 995 (POP3S) for mail servers, or 2083, 2087, and 2096 for cPanel, WHM, and webmail. Ports that use STARTTLS, like 25 and 587, are not supported yet.

Can I use it from a terminal?

▼

Yes. curl 'ipku.in/en/tools/ssl-check?q=example.com' returns the check as plain text, and /api/ssl/example.com returns JSON. Add &port=993 or ?port=993 for another port.