Wildcard SSL Checker — Verify Wildcard Cert Coverage

Verify wildcard certificate covers the right subdomains. Free wildcard ssl certificate checker.

The Wildcard SSL Checker verifies that a wildcard certificate (e.g. *.example.com) is correctly deployed and covers the subdomains you expect. A wildcard cert matches one level of subdomains (e.g. api.example.com, www.example.com) but not the apex (example.com) unless it is also in the SANs, and not nested subdomains (e.g. a.b.example.com) unless you have a separate cert or a multi-level wildcard where supported. This tool typically connects to the apex and several subdomains, reports which certificate is served and what names it covers, and highlights mismatches or missing coverage. Use it after issuing or renewing a wildcard cert to confirm all intended hostnames are valid, and to troubleshoot browser errors on specific subdomains.

Frequently Asked Questions

Does *.example.com cover example.com?

No. The apex is not covered by a single-level wildcard. Include example.com in SANs or use a separate cert.

What about a.b.example.com?

*.example.com covers one level (e.g. b.example.com). For a.b.example.com you need *.b.example.com or a separate cert.

How do I get a wildcard cert?

Most CAs support wildcards; Let's Encrypt requires DNS-01 challenge for wildcards.

Why does one subdomain fail?

That host might be pointing to a different server with a different cert, or the cert might not include that name.

Can I check multiple wildcards?

Run the checker for each domain or use a multi-domain SSL checker that supports wildcard validation.

More Ssl Tools

Explore Other Tool Hubs