drwho.me
Runs on our server

TLS certificate

Issuer, expiry, names and fingerprint.

The check runs on our server. We do not store the domain.

What this checks

This tool connects to the domain on port 443 and reads the TLS certificate the server presents: who it was issued to, who issued it, when it expires, every name it covers, and whether the chain validates against public certificate authorities.

What to look for

"Chain: not validated" means a browser would show a warning — a self-signed certificate, a certificate for the wrong name, or a broken chain of intermediate certificates are the common causes. Days remaining under 30 is worth renewing soon; a certificate that has already expired is validated by no one.

The fingerprint

The SHA-256 fingerprint identifies this exact certificate. It's useful for confirming two systems are serving the same certificate, or that a renewal actually rotated it.