Checking a website's SSL certificate expiry before the browser blocks it

Nothing destroys a site's credibility faster than a full-screen red page reading "Your connection is not private." And the most common cause of that page is one single thing — an expired SSL certificate. The good news is it's very easy to prevent: just know how many days are left on the certificate and check ahead of time, regularly.

What happens when SSL expires

When an SSL certificate expires, every browser (Chrome, Safari, Firefox, Edge) stops visitors at a warning page before they reach the site. Users have to accept the risk themselves to get in — and most simply close the tab and go elsewhere.

Why SSL expires sooner than you think

SSL certificate lifetimes keep getting shorter under industry standards. Paid certificates today can be issued for at most around 1 year, while the free and most popular Let's Encrypt lasts only 90 days. That means without an auto-renewal system, you have to remember the renewal date every 3 months.

SSL typeCertificate lifetimeAuto-renewal possible?
Let's Encrypt (free)90 daysYes — if Certbot / DirectAdmin is set up
DV SSL (paid)Up to ~1 yearDepends on the provider
OV / EV SSLUp to ~1 yearManual renewal + identity verification

How to check the SSL expiry date

Method 1 — Online tool (the easiest)

Just type a domain into a checker and it shows the expiry date, the issuer, and the number of days left. A domain health tool like dnsxray.com has an SSL section that displays the certificate status alongside DNS, email and WHOIS in a single lookup — one check shows everything, with no need to open several sites.

Method 2 — From the browser

Open the site, click the padlock icon next to the URL → view the certificate details. You'll see a "Valid until" field giving the date directly — handy for a quick one-site check.

Method 3 — The openssl command

For system administrators who want to check from the terminal:

echo | openssl s_client -servername example.com \
  -connect example.com:443 2>/dev/null \
  | openssl x509 -noout -dates

The output shows notBefore and notAfter — the notAfter line is the expiry date.

Understanding Certificate Chain Before You Check

The SSL certificate installed on your web server does not verify itself directly with browsers — it relies on a chain of trust made up of three layers: a Root CA, an Intermediate CA, and your own end-entity certificate. Understanding this structure tells you what to check beyond the expiry date alone.

LayerExampleTypical lifetimeEffect if expired
Root CADigiCert Global Root G220–30 yearsAll browsers distrust the site
Intermediate CARapidSSL TLS RSA CA G15–10 yearsChain broken — some devices error
End-entity (yours)example.com90 days – 1 yearSite gets blocked

Root and Intermediate CAs normally last long enough not to be a problem, but if the Intermediate Certificate is missing or not installed correctly, browsers show an "incomplete chain" error even though your primary certificate has not expired. Tools like dnsxray.com automatically report chain completeness alongside the expiry date.

Automated SSL Monitoring with curl and Python

If you manage many sites and need daily SSL monitoring without opening a browser for each one, you can script the checks and schedule them as cron jobs.

Method 4 — Check with curl (suitable for cron)

# Check expiry date with full certificate info
curl -v --head https://example.com 2>&1 | grep "expire date"

# Short form — expiry date only
curl -v --silent --head https://example.com 2>&1 \
  | grep "expire date"

Method 5 — Python script for multiple domains

import ssl, socket
from datetime import datetime

def check_ssl(hostname, port=443):
    ctx = ssl.create_default_context()
    with ctx.wrap_socket(socket.socket(), server_hostname=hostname) as s:
        s.settimeout(5)
        s.connect((hostname, port))
        cert = s.getpeercert()
    expires = datetime.strptime(cert['notAfter'], '%b %d %H:%M:%S %Y %Z')
    days_left = (expires - datetime.utcnow()).days
    return days_left, expires.strftime('%Y-%m-%d')

for domain in ['example.com', 'another-site.com']:
    days, date = check_ssl(domain)
    status = 'OK' if days > 30 else ('WARNING' if days > 0 else 'EXPIRED')
    print(f'{domain}: {status} — expires {date} ({days} days)')

This script can run via cron, for example daily, and send an email alert when fewer than 30 days remain on any domain.

DV, OV, and EV SSL — What's the Difference and How to Check Each

When auditing your SSL, you should also know which level of certificate your site uses, because each type has a different validation process and renewal timeline.

TypeWhat it verifiesIssuance timeBest for
DV (Domain Validation)Domain ownership onlyMinutesBlogs, startups, general websites
OV (Organization Validation)Domain + organization identity1–3 business daysBusiness websites, organizations
EV (Extended Validation)Full organization verification (company registry)3–7 business daysBanks, large e-commerce sites

DV renewal is fast and easy. OV and EV require fresh identity documentation each time, so start the renewal process at least 1–2 weeks before expiry — not just 30 days before.

Wildcard SSL and Multi-Domain SAN — What to Look For

Sites with multiple subdomains or multiple domain names often use one of two special certificate types. You need to verify that all covered names are still valid and correctly listed.

When inspecting the certificate details, always check the Subject Alternative Name field to confirm that every domain and subdomain in active use is covered. If you run both HTTP and HTTPS versions, test that HTTP redirects correctly to HTTPS on all domains.

Check more than just the "expiry date"

An unexpired SSL doesn't mean there's no problem. You should also check these three points.

The 30-day rule: aim to check SSL on every site at least once a month, and act on renewal when there are 30 or more days left. Don't wait until only a few days remain — some renewals (especially OV/EV) take several days for identity verification.

Set SSL to renew automatically

The best approach is not to have to remember at all — use auto-renewal.

Even with auto-renew set up, you should still check periodically, because auto-renew can fail silently (e.g. DNS changed or port 80 blocked).

Make checking a habit: open dnsxray.com and check your domain once a month, look at the SSL section for the days remaining, and renew early if it's close — and if you manage many sites, use the multi-domain check feature.

Frequently asked questions

Q: With free Let's Encrypt, do I have to renew every 90 days myself?

No, if auto-renew is set up — most DirectAdmin hosting renews it for you automatically. You just check periodically that it's actually working.

Q: Does the site disappear entirely when SSL expires?

The site is still there, but visitors hit a warning page first. Many won't click through — so you lose real traffic until you renew.

Q: I checked and there are 10 days left — what should I do?

If you use Let's Encrypt, trigger a renewal immediately (it usually finishes in minutes). If it's a paid SSL, contact the provider urgently, since identity verification can take time.

Q: Does AsiaGB manage SSL for me?

Yes — AsiaGB Hosting issues free SSL and sets up auto-renewal for you. For customers who want a paid SSL (DV/OV/EV), the team helps install it and reminds you before expiry.

Summary: an expired SSL is one of the top causes of a site being blocked. Prevent it by checking the expiry date once a month, renewing when 30+ days remain, and setting up auto-renew — but still re-check regularly, because auto-renew can fail silently.

Free SSL with auto-renewal on every plan

AsiaGB Hosting includes free SSL and sets up auto-renewal for every site — no more expired certificates. SSD Hosting from THB 500/year, 99% uptime, DirectAdmin.

View SSL Services