Check whether a certificate is valid
Read the certificate status for each hostname instead of assuming one domain covers every service.
Where Tools → Security → SSL/TLS Certificates → Status
Before you start
- List the hostnames people actually use: the main domain, www, mail and any other relevant names.
- A self-signed certificate can encrypt a connection but does not provide the normal public trust expected by browsers.
Steps
-
1
Open SSL/TLS Certificates and click Status in the top tab row.
-
2
Search for the hostname you want to check. Inspect each relevant domain separately.
-
3
Use View Certificate on the matching row to inspect the certificate details and covered names.
-
4
For a new managed certificate, use Wizard. For your own purchased certificate and matching private key, use Installation. Do not delete an installed certificate merely to refresh the page.
-
5
In this combined interface, Status is for inspection; AutoSSL actions are not shown there. Use the Wizard’s offered Let’s Encrypt workflow rather than looking for an older Run AutoSSL button.
-
6
Read Certificate Status and the expiry date. Self-signed is not the same as a publicly trusted certificate, even when its expiry is far in the future.
A hostname using a self-signed certificate.
Check it worked
- Open the actual HTTPS website and check for trust/name errors.
- For mail, test the hostname configured in the mail app; a working website URL does not prove the app’s server name is covered.