TLS certificate
Issuer, expiry, names and fingerprint.
The check runs on our server. We do not store the domain.
What this checks
This tool connects to the domain on port 443 and reads the TLS certificate the server presents: who it was issued to, who issued it, when it expires, every name it covers, and whether the chain validates against public certificate authorities.
What to look for
"Chain: not validated" means a browser would show a warning — a self-signed certificate, a certificate for the wrong name, or a broken chain of intermediate certificates are the common causes. Days remaining under 30 is worth renewing soon; a certificate that has already expired is validated by no one.
The fingerprint
The SHA-256 fingerprint identifies this exact certificate. It's useful for confirming two systems are serving the same certificate, or that a renewal actually rotated it.