Port & SSL/TLS Certificate Checker
Find out whether a port is reachable from the public internet and inspect the TLS certificate it serves — issuer, expiry countdown, subject alternative names, protocol version and cipher suite.
Check a host
Results
Enter a host and ports, then run the check.
Reachability and certificates in one pass
See which ports answer publicly and inspect every TLS-speaking service — issuer, expiry and SANs.
How to check an SSL certificate and open ports
Enter a host
Use a domain name or a public IP address. Paste a URL and the hostname is used.
Choose ports
Use a preset or type up to 10 ports. 443 is HTTPS; 8443, 465, 993 and 995 are other common TLS ports.
Read the results
Each port shows open or closed with latency. TLS ports show the certificate’s issuer, validity window, days remaining, SANs, TLS version and cipher.
What the check tells you
The check opens a real TCP connection to each port from our edge network — not from your browser — so results reflect what the public internet sees, not what’s reachable behind your firewall, VPN or NAT. If the port completes a TLS handshake, the certificate the server presents is parsed and summarised.
Reading certificate details
- Subject (CN) and SANs: the names the certificate is valid for. Browsers only trust the SAN list, so your hostname must appear there (wildcards like
*.example.comcover one level). - Issuer: the certificate authority, such as Let’s Encrypt, Sectigo or Google Trust Services.
- Expires in: turns amber under 21 days and red once expired. Automated renewals usually happen 30 days before expiry.
- Protocol and cipher: TLS 1.3 or 1.2 is expected today. TLS 1.0/1.1 are deprecated and should be disabled.
Common ports
| Port | Service | TLS? |
|---|---|---|
| 80 / 443 | HTTP / HTTPS | 443 yes |
| 22 | SSH | No (own protocol) |
| 25 / 465 / 587 | SMTP / SMTPS / submission | 465 yes · 587 STARTTLS |
| 993 / 995 | IMAPS / POP3S | Yes |
| 3306 / 5432 / 6379 / 27017 | MySQL / PostgreSQL / Redis / MongoDB | Shouldn’t be public |
Check a certificate from the command line with openssl s_client -connect example.com:443 -servername example.com </dev/null | openssl x509 -noout -dates -issuer -subject.
Frequently asked questions
How do I check when an SSL certificate expires?
Enter the domain, keep port 443 and run the check. The result shows the exact expiry date and how many days remain, with a warning when fewer than 21 days are left.
Why does a port show as closed when my service is running?
The check runs from the internet. A firewall, security group, NAT without port forwarding, or a service bound only to 127.0.0.1 will make the port unreachable from outside even though it works locally.
Are private or internal addresses blocked?
Yes. Loopback, private (RFC 1918), link-local and other internal ranges are rejected before any connection is attempted.
How many ports can I check at once?
Up to 10 per check, which keeps results fast and the service fair for everyone. Each closed port waits up to 4 seconds before timing out.
Is this a port scanner?
No. It checks only the specific ports you list on a single host, for diagnosing your own services. Please only check hosts you own or are authorised to test.