We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Inspect the certificate information, validity dates, hostname coverage, and chain-related findings presented by a public HTTPS endpoint.
Supports domain names, URLs with protocols, or host:port format. Default port is 443.
Active TLS checks send multiple probes. Scan only systems you own or are authorized to assess.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
A website certificate associates a public key with an identity and an issuer. After receiving the leaf certificate, a client builds a path through issuer certificates to a root in its local trust store.
A certificate can be within its validity period yet still fail for some clients because the hostname does not match, an intermediate is missing, a signature algorithm is unsupported, or the deployed chain differs by entry point. Conversely, a site opening in one browser does not prove that a new device, command-line client, or application can build the same trust path.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Provide the public hostname, IP address, or host:port used by the service.
The scan connects to the public endpoint and collects server-default and certificate findings returned by the scanner.
Review the subject, issuer, validity dates, SAN hostnames, and key details.
If a chain problem appears, inspect the leaf and intermediate certificates configured on the service and test again from the client environment that reported the error.
Use cases
See how the tool fits into real work and everyday tasks.
Review the validity window and certificate served by the public listener before expiry, then confirm that automated renewal or replacement reached the live endpoint.
When a browser works but a command-line client or mobile app reports an issuer error, inspect the server’s certificate clues and compare them with the failing client’s trust store and full error.
Check the www host, API subdomain, mail TLS endpoint, or regional hostname separately to find a certificate update that reached only some hosts or nodes.
Q&A
Find concise answers to common questions and confusing cases.
Expiry is only one condition.
Not conclusively.
The displayed lifetime is based on the certificate dates observed during the scan and the current time.
No.
Notes
Review scope, result limitations, and important precautions before use.
The scan sees the specified public host, port, and endpoint selected for that run.
A client decides whether to trust a chain using the certificates served, its trust anchors, validity dates, hostname matching, and local policy.
Scan only services you own or are authorized to assess.
Related
Discover related tools, collections, and available API capabilities.