Know every certificate you have, and the ones you forgot.

SSLScan reads the live certificate on every name you give it, finds the shadow subdomains you didn't from public Certificate Transparency logs, and tells you what's expiring, what's misconfigured, and exactly what breaks next. In plain language, not OpenSSL output.

Free plan, no card required. Read-only - SSLScan changes nothing on your systems.

See your renewal workload climb

A certificate has to be renewed before it expires - by someone, on time, every time. As the maximum lifetime falls from 398 days to 47, the same estate needs renewing far more often. Enter how many names you manage.

A working estimate: one certificate per name, each renewed at the maximum lifetime allowed. Wildcard and multi-name certificates lower the count; short-lived automation raises it. Why is this happening? →

What SSLScan does

Watch what matters

Enter the endpoints you care about, or import a server list from CSV or Excel. SSLScan reads the live certificate and tracks expiry, chain, key strength and hostname coverage.

Find what you forgot

Discover the subdomains already visible in Certificate Transparency - the shadow endpoints you never entered, surfaced from the public logs and checked live so you see the certificate each one actually serves.

Judge it correctly

Where a certificate lives and who issued it are separate questions. A public CA on an on-prem server is normal. An internal CA on a public address is not. SSLScan knows the difference, so the alerts stay worth reading.

Stop fighting OpenSSL

Upload a PFX, CRT, PEM or P7B and get back exactly what your target system needs - nginx, IIS, Tomcat, F5, Kubernetes, ACM. Your private key is processed in your browser and never reaches our servers.

You are letting a tool near your trust plane. That deserves specifics.

Read-only, alwaysSSLScan reads what your servers present. It never installs, binds, revokes or changes anything.
Private keys stay yoursThe toolkit runs in your browser; a monitor built on TLS handshakes never sees a private key. Structural, not a promise.
No keys to your systemsSSLScan needs no SSH, no service account, no API token. Nothing to leak, because nothing is held.
We store certificates, not secretsPublic certificate data and check results. Your card lives with our payment provider, never with us.

Simple pricing

One paid plan that lifts every limit. No per-certificate metering, so your bill does not grow just because certificate lifetimes shrank.

Free

To see whether your estate is in the state you think it is.

$0forever
No card required
  • 3 names watched, subdomains included
  • Expiry & security-posture checks
  • Subdomain discovery via Certificate Transparency
  • “What breaks next” projection
Start free

Prices in USD, excluding VAT or sales tax, which is calculated at checkout by our merchant of record. Full plan comparison and billing FAQ →

Questions people ask before signing up

Do you need access to my servers?

No. SSLScan reads certificates the same way a browser does - it opens a TLS connection and looks at what the server presents. No credentials, no SSH, no WMI, no agents on your machines. Nothing to leak, because nothing is held.

Can you see my private keys?

No, structurally. Reading a certificate over TLS never involves the private key - that is how TLS works. The toolkit does handle files that may contain one, such as a .pfx; that conversion happens entirely in your browser and is never uploaded.

How is this different from a free uptime monitor?

Uptime monitors tell you a certificate expires on a date - the easy part, and only for hosts you already knew about. SSLScan grades posture (chains, weak keys, hostname mismatches, deprecated TLS, self-signed on public addresses) and finds the shadow subdomains you never entered, from public Certificate Transparency logs.

What happens when the free trial ends?

The date of the first charge is shown in the product for the whole trial. Cancel before the trial ends and you pay nothing; your account returns to Free with your data intact - nothing is deleted because you stopped paying.

One domain, one minute, no card. Most people are surprised by the second screen.