Tools
SSL check
Checks a domain’s SSL certificate: validity, issuer, certificate chain and TLS version.
What the SSL check looks at
Like a browser, the SSL check opens an HTTPS connection to the domain you enter and reads the certificate the server presents. You see the same details a browser checks, just laid out more clearly.
- Issued to and Valid for (SAN): which domains the certificate covers, for example your-company.ch and www.your-company.ch.
- Issuer: which certificate authority signed the certificate.
- Valid from, valid until and days left: the latest date by which you need to renew.
- Certificate chain: whether the server sends all intermediate certificates and the chain leads to a trusted root certificate authority.
- TLS version: which protocol is used for the connection. TLS 1.2 and TLS 1.3 are current; older versions are considered insecure.
Common errors and their causes
The most common problem is an expired certificate. Often automatic renewal has stopped working, for example after a name server change or because the domain no longer points to the server. Just as often an address is missing: the certificate covers your-company.ch but not www.your-company.ch. An incomplete certificate chain, on the other hand, sometimes shows up only on certain devices, because some browsers fetch missing intermediate certificates themselves and others do not.
Shorter validity periods since 2026
Since 15 March 2026, publicly trusted certificates have been valid for at most 200 days. The CA/Browser Forum has agreed two further steps: 100 days from March 2027 and 47 days from March 2029. If you install certificates by hand, you will have to renew more and more often. Check expiry dates regularly or switch to automatic renewal.
Tip: At HostOn, a free SSL certificate is issued and renewed automatically for every domain in the hosting account. The only requirement is that the domain points to our server.
When a validated certificate is worth it
For most websites, the free certificate is enough. Validated OV and EV certificates also verify your company, for example for online shops or customer portals. A wildcard certificate covers all direct subdomains and the main domain. Validated certificates are available at HostOn from CHF 22.90 per year.
Frequently asked questions
Usually the certificate has expired, does not cover the address you opened (for example, the www version is missing) or the certificate chain is incomplete because an intermediate certificate is missing on the server. The SSL check shows which of these applies.
Since 15 March 2026, publicly trusted SSL certificates may be valid for no more than 200 days. Under the CA/Browser Forum’s decisions, the maximum drops to 100 days from 15 March 2027 and to 47 days from 15 March 2029.
SAN stands for Subject Alternative Name. This field lists every domain the certificate covers, for example your-company.ch and www.your-company.ch. Browsers only check this field. If the address you opened is not listed, a warning appears.
Renew the certificate and install it on the server together with the intermediate certificates. With automatically issued certificates, the cause is often that the domain no longer points to the server. Then use the SSL check to confirm that the new certificate is being served.

