Learn / updated 2026-10-04
What is an SSL/TLS certificate, and why does expiry matter?
An SSL/TLS certificate is what lets your browser connect to a website over HTTPS. It binds a domain name to a public key and is signed by a certificate authority (CA) that browsers trust. (SSL is the old name; TLS is the protocol in use today, and people still say "SSL certificate".)
What it contains
- the subject and the names it covers (the subject alternative names),
- the issuer, the CA that signed it,
- a validity period: not valid before, not valid after,
- the public key and the signature.
A browser checks that the name matches the site, that the certificate is inside its validity period, and that it chains up to a trusted CA.
What happens at expiry
When the "not valid after" date passes, browsers show a full-page warning and many API clients refuse to connect. For a website that is an outage; for an API it can break every integration at once. Nothing is wrong with the server: the certificate simply was not renewed.
Lifetimes keep getting shorter
Industry rules shorten the maximum lifetime of public certificates over time, and many certificates now last 90 days or less when issued through automated services. The practical consequence: renewal must be automated, and a failing renewal job is something to monitor, because there is less slack.
Certificate expiry is not domain expiry
The domain registration is a separate subscription with a registrar. If it lapses the domain can stop working altogether, and after a grace period it may be released. Monitor both dates.
What to monitor
- days left on each certificate you serve, with a warning at 30, 14 and 7 days,
- the domain registration expiry date,
- whether the certificate is trusted (a self-signed or wrongly chained certificate looks valid in dates but fails in browsers).
Checking quickly
The free SSL certificate checker shows the issuer, validity dates, days left and trust status plus the domain expiry for one domain. For lists of domains, use the API or put a live badge in your README.
Frequently asked questions
Is a valid certificate proof the site is safe? No. It proves the connection is encrypted and the domain matches; it says nothing about the site's content.
Why can two checks disagree? Sites can serve different certificates per hostname or location; a check sees the one presented to it.
Related
- SSL and Domain Expiry Sweep: API reference
- CPV codes and OCDS explained: how public tenders are described
- How EU VAT number validation works (VIES explained)
- SPF, DKIM and DMARC explained: how e-mail authentication works
- What is an LEI (Legal Entity Identifier)? Format, use and lookup
- All tools and prices
Informational only, not financial, legal or tax advice.