An SSL certificate (technically a TLS certificate) is the file that lets a website use HTTPS: it proves the site's identity and enables an encrypted connection. This guide explains what it is, how to see which certificate authority issued it, what free vs paid certificates change, and what happens when one expires.

1. What is an SSL certificate?

An SSL/TLS certificate is a small data file installed on a web server. It binds a domain name to a public key and is digitally signed by a trusted third party, the certificate authority (CA). When your browser connects, it checks that signature, the domain and the validity dates, then sets up encryption.

  • Encryption: data between visitor and server cannot be read in transit.
  • Authentication: visitors know they are talking to the real domain.
  • Integrity: pages cannot be modified on the way without detection.

"SSL" is the historical name; every modern site actually uses TLS 1.2 or 1.3. People still say "SSL certificate" — it means the same thing.

2. Which certificate authority issued a site's SSL certificate?

The issuer is written inside the certificate. Three quick ways to find it:

  • Online: enter the domain in our free SSL checker — it shows the issuer, subject and expiry date.
  • In the browser: click the icon left of the address bar → "Connection is secure" → "Certificate is valid" → Issued by.
  • Command line: openssl s_client -connect example.com:443 -servername example.com | openssl x509 -noout -issuer -dates

Common issuers are Let's Encrypt, Google Trust Services, Sectigo, DigiCert and GlobalSign. Sites behind a CDN often show the CDN's CA rather than the one the owner bought directly.

3. Types of certificates: DV, OV, EV, wildcard

  • DV (Domain Validated): proves control of the domain. Issued in minutes, often free. Fine for most sites.
  • OV (Organization Validated): the CA also verifies the company. Used by businesses that want the organization name in the certificate.
  • EV (Extended Validation): stricter checks; browsers no longer show a special green bar, so the visible benefit is small.
  • Wildcard (*.example.com) covers all first-level subdomains; SAN/multi-domain covers a list of names.

4. Free vs paid SSL certificates

Encryption strength is identical. Free certificates (Let's Encrypt, most hosting providers and CDNs) are DV only and last 90 days, so they rely on automatic renewal. Paid certificates add OV/EV validation, longer support contracts and warranties. For a typical website or SaaS, a free certificate with working auto-renewal is the right choice.

5. What happens when an SSL certificate expires?

Browsers block the page with a full-screen warning ("Your connection is not private"). Visitors leave, API clients and webhooks fail TLS validation, and payment or login flows break. Search engines may also drop rankings if the error lasts. Expiry is one of the most common — and most avoidable — causes of outages, usually because auto-renewal silently failed (DNS change, firewall, expired API token, server moved).

6. How to never miss an expiry

  • Check the expiry date now with the free SSL checker.
  • Turn on SSL monitoring to get alerts 30, 14 and 7 days before expiry.
  • Monitor every hostname, not just the main domain — API, CDN and mail subdomains often have separate certificates.

Read our complete SSL monitoring guide for a step-by-step setup.

Conclusion

An SSL certificate is cheap or free to get, but expensive to lose. Know who issued yours, make sure renewal is automated, and let a monitor warn you before the browser warns your customers.

Create a free UptimeFlux account — SSL and uptime checks for up to 5 monitors.