What this tool checks
- Chain validates to trusted roots
- Host name match (CN/SAN)
- Expiry date and days remaining
- Negotiated TLS version and cipher suite
- Whether TLS 1.0/1.1 are accepted
- Key type and size
- Certificate chain and self-signed certificates
How to use it
- 01
Enter a domain or subdomain (www.example.com).
- 02
Press Check; the tool connects to port 443.
- 03
If fewer than 30 days remain, check your renewal process.
Technical details
A real handshake
The tool connects with SNI and validates the chain against public roots the way a browser does. ALPN shows HTTP/2 support as well.
Legacy TLS test
A separate connection tests whether the server still accepts TLS 1.0 or 1.1. Both were deprecated by RFC 8996 and are not accepted by standards such as PCI DSS.
Automatic renewal
With short-lived certificates such as Let's Encrypt, the problem is rarely the certificate itself but a renewal job that silently stopped. That's why monitoring the remaining time matters.
Frequently asked questions
My certificate is valid but browsers still warn. Why?
Most often: a missing intermediate certificate on the server, a certificate issued for another host name, or resources loaded over HTTP (mixed content). Look at the chain and host name rows in the report.
Is a free certificate good enough?
For encryption, yes — free and paid DV certificates provide the same protection. The difference is validation type (OV/EV), support and warranty.
Is TLS 1.2 insecure?
Properly configured TLS 1.2 is secure. TLS 1.3 offers a faster handshake and removes weak options entirely; enable both where possible and disable 1.0 and 1.1.
Can I check a different port?
The tool works with the standard HTTPS port (443). For other services we run detailed TLS analysis as part of penetration testing.