SSL Certificate Badge

Show visitors a badge that A2Z actually checks: the certificate on your domain is inspected over a real TLS connection and the badge states the result - "valid, 43 days left", "expired" or "name mismatch" - never a vague "secure" seal.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
SSL Certificate Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

When the badge is requested, A2Z opens a TLS connection to your domain on port 443 using the same inspector as the A2Z SSL checker and reads the certificate your server presents. Three things are checked separately: the current time falls inside the certificate's notBefore/notAfter window; one of its subject alternative names covers your host name, either exactly or through a single-label wildcard such as *.example.com; and the chain builds to a root the server's operating-system trust store accepts. The outcome is cached for six hours, so your server sees a handful of connections a day however busy your pages are. Clicking the badge opens a public report listing the issuer, expiry date, protocol and each individual result.

What is checked

  • Valid period: notBefore <= now < notAfter (RFC 5280 section 4.1.2.5)
  • Name match: host equals a subjectAltName dNSName, or matches a wildcard in the left-most label only (RFC 9525)
  • Trusted chain: path builds to a trusted root with no chain errors; a self-signed leaf is never trusted
  • Days left = floor((notAfter - now) / 1 day); green above 14, amber at 14 or fewer, red when any check fails
  • Grey "unavailable" when A2Z could not connect - a failed check is never presented as a fault in your site

Worked examples

A healthy certificate

Inputs: Certificate for www.example.com and example.com, issued 10 days ago, notAfter 43.5 days from now, chain valid

Result: Green: "valid, 43 days left"

Days are rounded down, so 43.5 days shows as 43.

Wrong name

Inputs: example.com serves a certificate whose only name is other.com (common after a hosting move)

Result: Red: "name mismatch"

Browsers show a full-page warning in this case, so the badge says so plainly.

Renewal due

Inputs: Valid, trusted certificate with 10 days remaining

Result: Amber: "valid, 10 days left"

Most automated certificates renew around 30 days before expiry, so amber usually means renewal has stalled.

Limitations

  • Checks port 443 of the host name only - not other subdomains, ports or mail servers.
  • Revocation (OCSP/CRL) status is not queried; a revoked certificate that is otherwise valid still shows green.
  • Behind a load balancer or CDN, only the certificate from the server that answered A2Z is seen.
  • A valid certificate says nothing about the security of the website's code, data handling or other servers.

Where publishers use it

  • Online shops and booking sites that want a factual trust signal next to checkout
  • Web agencies showing clients that their certificates are watched
  • Hosting and SaaS status pages
  • Developers adding a certificate badge to a project README

Questions

Does a valid certificate mean my site is secure?

No, and the badge never says so. It states one fact: the HTTPS certificate is inside its validity period, names your domain and chains to a trusted root. Everything else about security is out of its scope.

How often is the badge updated?

The certificate is re-read when the cached result is more than six hours old, so a renewed certificate shows up within a few hours of being installed.

What happens if A2Z cannot reach my site?

The badge turns grey and says "unavailable". It only turns red when the certificate itself is expired, untrusted, not yet valid or issued for another name.

Can I use the badge in a GitHub README?

Yes. Copy the Markdown version; it is a plain SVG image with a link to the public report.

Sources

  1. RFC 5280 - X.509 certificate and CRL profile (validity period, path validation) - IETF
  2. RFC 9525 - Service identity in TLS (host-name matching and wildcards) - IETF . Supersedes RFC 6125.
  3. Baseline Requirements for publicly-trusted TLS certificates - CA/Browser Forum . Maximum certificate lifetimes and issuance rules.
  4. RFC 8446 - TLS 1.3 - IETF

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools SSL Certificate Badge
https://a2z.tools/ssl-certificate-checker

Preview