SSL Checker Widget
Add an SSL certificate checker to your website. Visitors type a domain and see whether its certificate is valid, trusted and issued for the right name, who issued it, which TLS version was negotiated and exactly when it expires.
Live preview
Exactly what your visitors will seeUnder the widget on your page: Powered by A2Z Tools
Embed code
<iframe src="https://a2z.tools/embed/w/ssl-checker" title="SSL Checker by A2Z Tools" width="100%" height="470" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>
A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.
<div data-a2z-widget="ssl-checker" data-height="470"></div> <script async src="https://a2z.tools/embed.js"></script>
Adds a small script (what it does) that sizes the widget to fit its content, loads it lazily and keeps it isolated from your page's CSS.
Works with
How it works
The widget sends the domain to A2Z, which resolves it once, refuses private or reserved addresses, and opens a TLS connection on port 443 with the same inspector as the full A2Z SSL checker. It returns four separate facts - validity window, host-name match, chain trust and days remaining - plus the issuer and negotiated protocol, each with its own OK, Attention or Problem label so colour is never the only signal. Every result links to a public report page, and results are cached for six hours so a popular help article does not hammer the checked site.
What is checked
- Validity: notBefore <= now < notAfter (RFC 5280); host match per RFC 9525, wildcards in the left-most label only
- Trust: chain builds to a trusted root with no errors; self-signed certificates are never trusted
- Checks are rate-limited per visitor on cache misses and capped at six concurrent checks on A2Z's side
Worked examples
A typical Let's Encrypt site
Inputs: example.org with a 90-day certificate issued 30 days ago
Result: OK - valid, 60 days left; Issuer: Let's Encrypt; Protocol: TLS 1.3
The issuer shown is the organisation name from the issuing certificate.
A self-signed test server
Inputs: staging.example.org serving a self-signed certificate
Result: Problem - untrusted; Trusted chain: no (self-signed)
Browsers show a warning page for this case, which is why it is reported as a problem.
A private address
Inputs: a name that resolves to 10.0.0.5
Result: Unavailable - resolves to an address A2Z does not check
Internal addresses are never contacted, so nothing about them is reported.
Limitations
- Port 443 only; other ports need the full A2Z SSL checker.
- Revocation (OCSP/CRL) is not queried.
- No vulnerability scanning - protocol and certificate facts only.
- IP addresses and internal host names are refused.
Where publishers use it
- Hosting companies' help centres
- IT support blogs explaining certificate errors
- Web agency tools pages
Questions
Can I see every certificate ever issued for my domain?
Not here. Public Certificate Transparency logs record every publicly trusted certificate; searching them shows certificates you did not expect, such as ones obtained by a former provider. This widget only reads the certificate your server presents now.
What does a missing intermediate certificate look like here?
The chain check fails with an untrusted result even though the certificate itself is fine. Desktop browsers sometimes hide this by fetching or caching the intermediate, while Android apps and API clients reject it, so it is worth fixing on the server.
Does the key type (RSA or ECDSA) matter for the result?
No. Both RSA and ECDSA certificates are checked the same way. The key algorithm and size appear in the full report for reference but do not change the verdict.
Why does the result mention SNI?
A2Z sends the domain name in the TLS handshake (Server Name Indication), as browsers do. A server hosting many sites uses it to pick the right certificate; an old server without SNI support may return a default certificate for another name.
Can it check a port other than 443?
Not in the widget. The full A2Z SSL checker supports other ports and shows the whole certificate chain.
Does it test for vulnerabilities?
No. It reports certificate and protocol facts only; a clean result is not a security audit.
Why was my check refused?
IP addresses, internal names such as .local or .internal, and names that resolve to private addresses are not checked, to keep the service from being used to probe private networks.
Sources
- RFC 5280 - X.509 certificate and CRL profile (validity period, path validation) - IETF
- RFC 9525 - Service identity in TLS (host-name matching and wildcards) - IETF . Supersedes RFC 6125.
- RFC 8446 - TLS 1.3 - IETF
- Baseline Requirements for publicly-trusted TLS certificates - CA/Browser Forum . Maximum certificate lifetimes and issuance rules.
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools SSL Checker https://a2z.tools/ssl-certificate-checker
<a href="https://a2z.tools/ssl-certificate-checker">A2Z Tools SSL Checker</a>
[A2Z Tools SSL Checker](https://a2z.tools/ssl-certificate-checker)
SSL Checker by A2Z Tools - https://a2z.tools/ssl-certificate-checker
Related widgets
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
Visitors enter a domain and see which of six key security headers it sends.
-
Checks a domain's SPF and DMARC records and DNSSEC status in one go.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.