Enter a domain to check its SSL/TLS certificate. This tool connects to the domain from our server — we do not log or store what you check.
We do not log or store the domains you check.
the domain you enter, via our server (a direct TLS handshake, not a page fetch)
Connecting…
How This Tool Works
This tool makes a real TLS handshake to the domain you enter, from our server, and reads the certificate it presents — who it was issued to, who issued it, its validity window, and every domain it covers (its Subject Alternative Names). Unlike a normal HTTPS request, this tool deliberately does not reject an invalid, expired, or self-signed certificate — its whole purpose is showing you exactly what’s being presented, even when something’s wrong with it, so you can see the problem yourself.
FAQ
What happens if a certificate has expired?
This tool still shows it to you, clearly marked as expired — most browsers would block the connection with a warning page instead, which is correct for browsing but not useful for diagnosing the problem.
What are Subject Alternative Names (SANs)?
The full list of domains (and subdomains) a single certificate is valid for — a certificate for “example.com” might also cover “www.example.com” via its SAN list, for instance.
Do you store the domains I check?
No — we do not log or store the domains you check with this tool.