ambolt

Learn / updated 2026-10-04

What is an SSL/TLS certificate, and why does expiry matter?

An SSL/TLS certificate is what lets your browser connect to a website over HTTPS. It binds a domain name to a public key and is signed by a certificate authority (CA) that browsers trust. (SSL is the old name; TLS is the protocol in use today, and people still say "SSL certificate".)

What it contains

A browser checks that the name matches the site, that the certificate is inside its validity period, and that it chains up to a trusted CA.

What happens at expiry

When the "not valid after" date passes, browsers show a full-page warning and many API clients refuse to connect. For a website that is an outage; for an API it can break every integration at once. Nothing is wrong with the server: the certificate simply was not renewed.

Lifetimes keep getting shorter

Industry rules shorten the maximum lifetime of public certificates over time, and many certificates now last 90 days or less when issued through automated services. The practical consequence: renewal must be automated, and a failing renewal job is something to monitor, because there is less slack.

Certificate expiry is not domain expiry

The domain registration is a separate subscription with a registrar. If it lapses the domain can stop working altogether, and after a grace period it may be released. Monitor both dates.

What to monitor

Checking quickly

The free SSL certificate checker shows the issuer, validity dates, days left and trust status plus the domain expiry for one domain. For lists of domains, use the API or put a live badge in your README.

Frequently asked questions

Is a valid certificate proof the site is safe? No. It proves the connection is encrypted and the domain matches; it says nothing about the site's content.

Why can two checks disagree? Sites can serve different certificates per hostname or location; a check sees the one presented to it.

Related

Informational only, not financial, legal or tax advice.