Decode PEM/x509 certificates offline or inspect live SSL/TLS certificate chains with expiration countdowns and health checks.
Free SSL/TLS certificate decoder and health checker. Decode raw PEM/X.509 certificates in your browser air-gapped with zero network transmission, or test any live domain for TLS protocol version, cipher suite, full certificate chain (Leaf → Intermediate → Root), SANs, expiration countdown, and DNS CAA records. Includes security health scoring and interactive wildcard hostname matching.
Keywords: ssl certificate decoder, ssl checker online, x509 decoder, cert decoder, ssl decoder online, tls checker, view pem cert, check ssl expiration, ssl certificate chain viewer, subject alternative name checker, caa record check, ssl security health audit
Tags: ssl, tls, certificate, x509, pem, https, security, crypto, san, caa
SSL/TLS Certificate Decoder is also known as: X.509 Certificate Decoder, SSL Checker Online, TLS Certificate Inspector, PEM Certificate Viewer, SSL Expiration Checker.
Select your operational mode: choose "Live Domain Check" to query an active HTTPS endpoint, or "Decode PEM" to parse raw certificate files offline.
For live domains, enter any fully qualified domain name (e.g., example.com, api.domain.org) and optional port (defaults to 443), then click "Check SSL Certificate".
For offline decoding, paste your PEM-formatted certificate block (beginning with -----BEGIN CERTIFICATE-----) or click "Upload .CRT / .PEM" to load a file directly from your machine.
Review the Expiration Status & Timeline bar to inspect the certificate start date, expiration date, total lifetime in days, and real-time days remaining.
Examine the Subject and Issuer cards to verify the Common Name (CN), Organization (O), Organizational Unit (OU), Country (C), State/Province (ST), Locality (L), and Serial Number.
Switch to the "Chain" tab to audit the full Certificate Chain of Trust (Leaf Server Certificate → Intermediate CA → Root CA) and verify cryptographic signature paths.
Check the "Health" tab for an automated security health rating (0–100 with A+ to F grades) evaluating key size, signature algorithm, expiration status, and DNS CAA records.
Use the interactive "Hostname Coverage Checker" to test whether specific subdomains, multi-level domains, or wildcards (*.example.com) are validly secured.
Click "Copy Report" or "Copy PEM / JSON" to export the structured audit results into tickets, configuration files, or compliance reports.
Dual-mode operation: 100% client-side air-gapped PEM decoder + high-performance server-side live domain TLS inspector.
Comprehensive ASN.1 DER parser: decodes standard X.509 v1, v2, and v3 certificates, multi-certificate bundles, and raw DER base64 streams.
Live expiration countdown & lifetime progress bar: visual timeline showing percentage elapsed, days remaining, start date, and expiry date.
Multi-algorithm cryptographic support: decodes RSA (1024, 2048, 3072, 4096-bit), Elliptic Curve (ECDSA P-256, P-384, P-521), Ed25519, and Ed448.
Subject Alternative Name (SAN) inspection: full extraction of DNS names, IPv4/IPv6 addresses, RFC822 email addresses, and URIs with search and one-click copy.
Visual certificate chain hierarchy: renders interactive Leaf (Server), Intermediate CA, and Root CA trees with trust authorization validation.
Automated security health score & grading: assigns 0–100 scores and A+ to F grades checking for weak hashes (MD5, SHA-1), undersized keys, and upcoming expiration.
RFC 6125 wildcard hostname matching: interactive tester verifies if subdomains and microservices match certificate SANs or wildcard patterns (*.domain.com).
DNS CAA record resolution: queries and analyzes Certification Authority Authorization records (RFC 6844) to verify permitted certificate issuers.
Multi-format cryptographic fingerprints: generates SHA-256, SHA-1, and MD5 fingerprints in both colon-separated hex and raw formats.
Full X.509 extension parsing: Basic Constraints (CA flag, Path Length), Key Usage flags, Extended Key Usage (Server Auth, Client Auth, Code Signing), SKI, and AKI.
Revocation & Authority endpoint discovery: extracts Authority Information Access (AIA) OCSP responder URLs, CA Issuers URLs, and CRL Distribution Points.
TLS protocol & cipher suite detection: identifies negotiated TLS version (TLS 1.2, TLS 1.3) and cipher suite parameters on live connections.
Recent check history: local storage history allows one-click re-runs of recent domain checks without transmitting search logs to external databases.
Zero-knowledge air-gapped privacy: pasted certificates and sensitive internal cryptographic blocks remain strictly on your local browser in PEM mode.
One-click multi-format export: export parsed certificate metadata as structured JSON, cleaned PEM, or formatted text audit reports.
The SSL/TLS Certificate Decoder supports 5 SQL dialects. Select the right dialect for accurate formatting and keyword recognition.