How to: Check SSL with SSL Shopper SSL Checker

SSL certificate check

Open SSL Shopper and enter your public server hostname

SSL Shopper’s SSL Checker tests the certificate presented by a public server. Enter a hostname such as www.example.com, not a full page address. The report checks installation, expiry, hostname coverage, browser trust and the intermediate certificate chain.

InstalledA certificate is presented
DATEValid datesNot expired or premature
DNSHostnameThe name is covered
CHAINBrowser trustIntermediates are supplied

How to use SSL Shopper SSL Checker

  1. 1
    Open the official SSL Checker

    Use the button above or visit the SSL Shopper SSL Checker page directly.

  2. 2
    Enter the public hostname

    Type the server name only, such as www.example.com. SSL Shopper says internal hostnames are not supported.

  3. 3
    Select Check SSL

    The service connects to the public server and displays the certificate it receives.

  4. 4
    Review every hostname you use

    Test the root domain, the www version and any separate webmail or control-panel hostname that visitors use.

How to read the SSL Shopper results

ResultWhat it meansWhat to do
Certificate is installedThe server presented a certificate during the TLS connection.Continue checking the hostname, dates and chain.
Hostname matchesThe tested name is included in the certificate’s subject alternative names.Test other names, such as www, separately.
Certificate is validThe current date is within the certificate’s validity period.Confirm that automatic renewal is working.
Trusted certificateThe certificate chains to a certificate authority recognised by common clients.Check on real browsers and devices if users still report warnings.
Intermediate certificates suppliedThe server provides the chain a client needs to reach a trusted root.Install the correct full chain if intermediates are missing.

SSL Shopper may cache repeated checks for up to a day. If a certificate has just been replaced and the report still shows the old one, verify the result in a browser and test again later.

Common SSL errors and how to fix them

No SSL

No certificate is found

Confirm that HTTPS is enabled, a certificate is assigned to the website and the server is listening on port 443. Check that DNS points to the intended server.

Expired

The certificate has expired

Renew or reissue it, install the replacement and confirm that automated renewal can complete. Check DNS validation and any security rule that could block renewal.

Name

The hostname does not match

Issue a certificate that includes the exact hostname visitors use. The root domain, www, webmail and other subdomains are separate names unless covered.

Chain

An intermediate is missing

Install the full certificate chain supplied by the certificate authority. A leaf certificate by itself may work on some devices and fail on others.

Wrong site

The server shows another certificate

Check the hosting assignment, virtual host, proxy, load balancer or content delivery network. One of those services may be presenting the wrong certificate.

Warning

The checker passes but the page warns

Test the exact hostname and inspect the browser warning. Mixed content, an old cached certificate, a local clock problem or a different network route can cause a separate issue.

How UKC hosting customers manage SSL in Plesk

UKC web hosting includes Plesk Obsidian and SSL certificate tools. In Plesk, open Websites & Domains, choose the domain, then open SSL/TLS Certificates. The SSL It! interface shows the current security status and can issue a free Let’s Encrypt certificate where the domain and DNS are ready.

1Check DNS first

The domain and each selected hostname must resolve to the hosting service that will answer the validation request.

2Select the required names

Include the root domain, www and any webmail or wildcard coverage that the website actually needs.

3Issue and assign the certificate

Use SSL/TLS Certificates to install it, then confirm the correct certificate is assigned to the site.

4Test before enforcing HTTPS

Make sure every important page works over HTTPS before enabling a permanent redirect or HSTS.

What SSL Shopper does not test

The checker is excellent for installation and trust-chain checks, but a successful result is not a complete website security audit. It does not prove that an application is free from vulnerabilities, that every page avoids mixed content, or that all supported TLS protocols and ciphers are configured optimally.

Use SSL Shopper for
  • Installation and expiry checks
  • Hostname coverage
  • Intermediate certificate problems
  • Basic browser trust
Use additional checks for
  • Protocols and cipher configuration
  • Application vulnerabilities
  • Mixed content on individual pages
  • Security headers and application policy

SSL checker questions

Should I enter https:// before the hostname?

No. SSL Shopper currently asks for the public server hostname, such as www.example.com, rather than a full URL.

Why should I test both example.com and www.example.com?

They are separate hostnames. A certificate may include one, both or a wildcard pattern. Test every name visitors and applications use.

Does a valid SSL certificate make a website safe?

It encrypts the connection and confirms control of the covered hostname according to the certificate type. It does not prove that the website, business or application content is trustworthy or vulnerability-free.

What is a certificate chain?

It is the sequence from the website certificate through one or more intermediate certificates to a trusted root. The server normally sends the website certificate and the required intermediates.

Why does SSL Shopper show an old certificate?

Repeated results may be cached for up to a day. Also check whether a proxy, CDN or load balancer is still serving the previous certificate.

Can SSL Shopper check an internal server name?

No. SSL Shopper states that internal hostnames are not supported. Internal services need a suitable local or command-line test performed by an authorised administrator.

Checker behaviour was verified against the current SSL Shopper SSL Checker. UKC Plesk steps follow the current Plesk SSL It! guide.

Hosting with SSL tools included

Compare UKC web hosting plans

Review plans with Plesk Obsidian, SSL tools, security features and UKC support. Check the current term, VAT and total before ordering.

Was this helpful?
How to: Check SSL with SSL Shopper SSL Checker written by UKC average rating 4.3/5 - 6 user ratings