SSL and domain expiry checker
These are the boring disasters. A lapsed certificate or registration takes the whole site offline rather than costing a few rankings, and both fail on a date that was known months in advance. This reads the live certificate and the public registry record.
Reads the live TLS certificate and the public registry record. No account needed. Rate limited to 60 checks an hour per IP.
Illustrative result for a reserved example domain. Your check replaces it.
TLS certificate
Valid for 84 more days
- Issuer
- Let's Encrypt R3
- Expires
- 2026-11-14
- Matches this host
- yes
Domain registration
Registered for 164 more days
- Registrar
- Example Registrar, Inc.
- Expires
- 2027-02-02
What this check means
- TLS certificate
- A TLS certificate is the file that proves a site owns its domain, letting browsers connect over HTTPS.
- Certificate expiry
- Certificate expiry is the date after which browsers and crawlers reject the certificate and refuse the connection.
- Domain registration expiry
- Domain registration expiry is the date a domain name stops being registered to its owner, after which it stops resolving.
- RDAP
- RDAP is the public protocol registries use to publish registration data, including the expiry date, in a machine-readable form.
How to read the result
- Certificate verdict
- Thirty days or fewer is marked for review and seven or fewer is critical. A certificate that fails to verify or does not match the host is critical whatever its expiry date.
- Matches this host
- A certificate can be valid and still be issued for a different name. When this reads no, browsers reject it exactly as they would an expired one.
- Domain verdict
- Forty-five days or fewer is marked for review and fourteen or fewer is critical, because domain recovery after a lapse is slower than certificate renewal.
- Registry did not answer
- This means no RDAP data was returned, usually because the registry publishes none. It is not a statement that the domain is fine.
Common causes
- A card on the registrar or certificate account expired and auto-renewal failed silently.
- Renewal notices went to a former employee or a shared mailbox nobody reads.
- An automated certificate renewal broke when a validation path changed, for example a redirect added in front of the challenge.
- The domain sits in a different account from the hosting, so nobody treats it as their responsibility.
- A certificate was reissued for a new hostname and the old host was left on the previous one.
What happens to SEO when an SSL certificate expires?
Browsers show a full-page security warning and most visitors leave. Crawlers cannot complete the request either, so pages stop being refreshed and can eventually be dropped. It is an outage, not a ranking penalty, which is why it is more damaging than most SEO problems.
What happens when a domain registration expires?
The domain stops resolving, so the site, its email and any links pointing at it all fail at once. Registries then hold the name for a redemption period with a higher fee before releasing it, so recovery is slower and more expensive than renewal.
Does auto-renewal make this safe to ignore?
No. Auto-renewal fails quietly when a card expires, a billing address changes, or a renewal email lands in a filtered mailbox. The certificate or domain lapses on schedule regardless, and nobody finds out until the site is already down.
How many days of warning are enough?
Thirty days for a certificate and forty-five for a domain leaves room to notice, find who controls the account, and act. This checker uses those thresholds, matching what the paid monitoring alerts on.
Why can this tool not find some domain expiry dates?
It reads RDAP, the public registry protocol. Many country-code registries publish no RDAP service, so no expiry date exists to read. The tool says the registry did not answer rather than presenting a guess as a fact.
