TLS certificate checker
Catch expiring or misconfigured certificates before browsers start warning your visitors.
How it measures
- A validated TLS handshake with SNI set to the hostname decides whether the certificate is trusted.
- If validation fails, a second diagnostic handshake captures the presented certificate so you can see why, without ever marking it as valid.
- Days remaining are computed from the certificate's notAfter value against the current time (UTC).
Limits
- Only implicit TLS ports are supported; STARTTLS negotiation is not performed.
- Trust is evaluated against the public root store of the checking host; private CAs show as untrusted.
- One check from one location; some servers present different certificates per region or client.
Troubleshooting
- Hostname mismatch
- The certificate's names do not include the hostname you connected to. Add the name as a SAN or point the hostname at the correct server.
- Untrusted chain
- An intermediate certificate is probably missing. Serve the full chain, not just the leaf.
- Expired
- Renew the certificate. Automate renewal and monitor expiry so this does not recur.