
Nothing destroys a site's credibility faster than a full-screen red page reading "Your connection is not private." And the most common cause of that page is one single thing — an expired SSL certificate. The good news is it's very easy to prevent: just know how many days are left on the certificate and check ahead of time, regularly.
What happens when SSL expires
When an SSL certificate expires, every browser (Chrome, Safari, Firefox, Edge) stops visitors at a warning page before they reach the site. Users have to accept the risk themselves to get in — and most simply close the tab and go elsewhere.
- Traffic drops immediately on the day the certificate expires
- Online stores can't sell at all during the blocked period
- Google sees the site as having a security problem, which can hurt rankings
- Any API or app that calls the site over HTTPS will error out entirely
Why SSL expires sooner than you think
SSL certificate lifetimes keep getting shorter under industry standards. Paid certificates today can be issued for at most around 1 year, while the free and most popular Let's Encrypt lasts only 90 days. That means without an auto-renewal system, you have to remember the renewal date every 3 months.
| SSL type | Certificate lifetime | Auto-renewal possible? |
|---|---|---|
| Let's Encrypt (free) | 90 days | Yes — if Certbot / DirectAdmin is set up |
| DV SSL (paid) | Up to ~1 year | Depends on the provider |
| OV / EV SSL | Up to ~1 year | Manual renewal + identity verification |
How to check the SSL expiry date
Method 1 — Online tool (the easiest)
Just type a domain into a checker and it shows the expiry date, the issuer, and the number of days left. A domain health tool like dnsxray.com has an SSL section that displays the certificate status alongside DNS, email and WHOIS in a single lookup — one check shows everything, with no need to open several sites.
Method 2 — From the browser
Open the site, click the padlock icon next to the URL → view the certificate details. You'll see a "Valid until" field giving the date directly — handy for a quick one-site check.
Method 3 — The openssl command
For system administrators who want to check from the terminal:
echo | openssl s_client -servername example.com \
-connect example.com:443 2>/dev/null \
| openssl x509 -noout -dates
The output shows notBefore and notAfter — the notAfter line is the expiry date.
Understanding Certificate Chain Before You Check
The SSL certificate installed on your web server does not verify itself directly with browsers — it relies on a chain of trust made up of three layers: a Root CA, an Intermediate CA, and your own end-entity certificate. Understanding this structure tells you what to check beyond the expiry date alone.
| Layer | Example | Typical lifetime | Effect if expired |
|---|---|---|---|
| Root CA | DigiCert Global Root G2 | 20–30 years | All browsers distrust the site |
| Intermediate CA | RapidSSL TLS RSA CA G1 | 5–10 years | Chain broken — some devices error |
| End-entity (yours) | example.com | 90 days – 1 year | Site gets blocked |
Root and Intermediate CAs normally last long enough not to be a problem, but if the Intermediate Certificate is missing or not installed correctly, browsers show an "incomplete chain" error even though your primary certificate has not expired. Tools like dnsxray.com automatically report chain completeness alongside the expiry date.
Automated SSL Monitoring with curl and Python
If you manage many sites and need daily SSL monitoring without opening a browser for each one, you can script the checks and schedule them as cron jobs.
Method 4 — Check with curl (suitable for cron)
# Check expiry date with full certificate info
curl -v --head https://example.com 2>&1 | grep "expire date"
# Short form — expiry date only
curl -v --silent --head https://example.com 2>&1 \
| grep "expire date"
Method 5 — Python script for multiple domains
import ssl, socket
from datetime import datetime
def check_ssl(hostname, port=443):
ctx = ssl.create_default_context()
with ctx.wrap_socket(socket.socket(), server_hostname=hostname) as s:
s.settimeout(5)
s.connect((hostname, port))
cert = s.getpeercert()
expires = datetime.strptime(cert['notAfter'], '%b %d %H:%M:%S %Y %Z')
days_left = (expires - datetime.utcnow()).days
return days_left, expires.strftime('%Y-%m-%d')
for domain in ['example.com', 'another-site.com']:
days, date = check_ssl(domain)
status = 'OK' if days > 30 else ('WARNING' if days > 0 else 'EXPIRED')
print(f'{domain}: {status} — expires {date} ({days} days)')
This script can run via cron, for example daily, and send an email alert when fewer than 30 days remain on any domain.
DV, OV, and EV SSL — What's the Difference and How to Check Each
When auditing your SSL, you should also know which level of certificate your site uses, because each type has a different validation process and renewal timeline.
| Type | What it verifies | Issuance time | Best for |
|---|---|---|---|
| DV (Domain Validation) | Domain ownership only | Minutes | Blogs, startups, general websites |
| OV (Organization Validation) | Domain + organization identity | 1–3 business days | Business websites, organizations |
| EV (Extended Validation) | Full organization verification (company registry) | 3–7 business days | Banks, large e-commerce sites |
DV renewal is fast and easy. OV and EV require fresh identity documentation each time, so start the renewal process at least 1–2 weeks before expiry — not just 30 days before.
Wildcard SSL and Multi-Domain SAN — What to Look For
Sites with multiple subdomains or multiple domain names often use one of two special certificate types. You need to verify that all covered names are still valid and correctly listed.
- Wildcard SSL (
*.example.com) — One certificate covers every subdomain, such aswww.example.com,shop.example.com, andmail.example.com. It does NOT cover the bare domainexample.comor sub-subdomains likea.b.example.com. - Multi-Domain SAN (Subject Alternative Names) — A single certificate explicitly lists multiple separate domain names, for example
example.com,example.net, andmybrand.co.th.
When inspecting the certificate details, always check the Subject Alternative Name field to confirm that every domain and subdomain in active use is covered. If you run both HTTP and HTTPS versions, test that HTTP redirects correctly to HTTPS on all domains.
Check more than just the "expiry date"
An unexpired SSL doesn't mean there's no problem. You should also check these three points.
- Issued for the right domain — the certificate must cover the name actually used (e.g. both
example.comandwww.example.com) - Complete certificate chain — if the intermediate certificate is missing, some devices will treat the SSL as untrusted
- Still uses secure algorithms — a very old certificate may use a standard that newer browsers no longer accept
The 30-day rule: aim to check SSL on every site at least once a month, and act on renewal when there are 30 or more days left. Don't wait until only a few days remain — some renewals (especially OV/EV) take several days for identity verification.
Set SSL to renew automatically
The best approach is not to have to remember at all — use auto-renewal.
- Let's Encrypt: set Certbot to run via cron, or enable the auto-renew feature in DirectAdmin
- Good hosting: usually issues and renews Let's Encrypt automatically with no action from the customer
- Paid SSL: set a calendar reminder 45 days ahead, since most can't be auto-renewed
Even with auto-renew set up, you should still check periodically, because auto-renew can fail silently (e.g. DNS changed or port 80 blocked).
Make checking a habit: open dnsxray.com and check your domain once a month, look at the SSL section for the days remaining, and renew early if it's close — and if you manage many sites, use the multi-domain check feature.
Frequently asked questions
Q: With free Let's Encrypt, do I have to renew every 90 days myself?
No, if auto-renew is set up — most DirectAdmin hosting renews it for you automatically. You just check periodically that it's actually working.
Q: Does the site disappear entirely when SSL expires?
The site is still there, but visitors hit a warning page first. Many won't click through — so you lose real traffic until you renew.
Q: I checked and there are 10 days left — what should I do?
If you use Let's Encrypt, trigger a renewal immediately (it usually finishes in minutes). If it's a paid SSL, contact the provider urgently, since identity verification can take time.
Q: Does AsiaGB manage SSL for me?
Yes — AsiaGB Hosting issues free SSL and sets up auto-renewal for you. For customers who want a paid SSL (DV/OV/EV), the team helps install it and reminds you before expiry.
Summary: an expired SSL is one of the top causes of a site being blocked. Prevent it by checking the expiry date once a month, renewing when 30+ days remain, and setting up auto-renew — but still re-check regularly, because auto-renew can fail silently.
Free SSL with auto-renewal on every plan
AsiaGB Hosting includes free SSL and sets up auto-renewal for every site — no more expired certificates. SSD Hosting from THB 500/year, 99% uptime, DirectAdmin.
View SSL Services