SSL · TLS · HSTS · CAA
SSL certificate checker
Enter a domain to inspect its certificate, chain and TLS configuration on port 443. Every result comes straight from the server at the time of the check.
What does the SSL checker test?
- Certificate: whether the chain is trusted, whether it covers the name you entered, and how many days are left until it expires.
- Chain: every certificate from the server certificate up to the root, with key type and signature algorithm.
- Protocols: which of TLS 1.0, 1.1, 1.2 and 1.3 the server accepts, plus the negotiated cipher suite and HTTP version.
- HTTP security: the HSTS header, whether plain HTTP redirects to HTTPS, OCSP stapling and the CAA records in DNS.
Frequently asked questions
›Why should TLS 1.0 and 1.1 be disabled?
Both versions are deprecated (RFC 8996) and modern browsers no longer use them. Leaving them on only helps outdated clients and attackers; TLS 1.2 and 1.3 are enough.
›What is HSTS?
Strict-Transport-Security tells browsers to use only HTTPS for the site for the given time, so a visitor is never downgraded to plain HTTP.
›What are CAA records?
DNS records that list which certificate authorities may issue certificates for the domain. Without them, any authority may.
›Does the check store anything?
Only the result, in a short-lived cache (10 minutes) so repeated checks are fast. "Check again" bypasses it.