§ TLS — certificate

The certificate on the port

Who issued it, when it expires, and how many days remain — read straight off a live handshake rather than a cached scrape. Free, no signup, 5 checks a day.

5 free checks a day. No signup, no key.

Try one:
§ Reference — what this check means

The certificate is a deadline, not a detail

01

What the check reads

The certificate is fetched in a live handshake on port 443: who issued it, when it expires, how many days remain, and whether it validates. The answer is what browsers actually get, not what a control panel claims.

02

The 30-day renewal rule

Automated renewal usually fires at 30 days remaining. Under 14 days is flagged amber here, and anything already past its date is red — an expired certificate has usually been failing quietly for a while, because renewals break silently more often than anyone expects.

03

Wildcard certificates

A *.domain certificate covers every host under the name without ever naming one, so individual hostnames stop reaching public certificate logs. That hides subdomains from passive discovery — it is a blind spot, not a breach.

04

What the error column means

No answer means the port refused the handshake or the name carries no certificate at all. A refused connection is a server configuration question, not a certificate one, and it is reported as such.