The certificate on the port
Who issued it, when it expires, and how many days remain — read straight off a live handshake rather than a cached scrape. Free, no signup, 5 checks a day.
5 free checks a day. No signup, no key.
The certificate is a deadline, not a detail
What the check reads
The certificate is fetched in a live handshake on port 443: who issued it, when it expires, how many days remain, and whether it validates. The answer is what browsers actually get, not what a control panel claims.
The 30-day renewal rule
Automated renewal usually fires at 30 days remaining. Under 14 days is flagged amber here, and anything already past its date is red — an expired certificate has usually been failing quietly for a while, because renewals break silently more often than anyone expects.
Wildcard certificates
A *.domain certificate covers every host under the name without ever naming one, so individual hostnames stop reaching public certificate logs. That hides subdomains from passive discovery — it is a blind spot, not a breach.
What the error column means
No answer means the port refused the handshake or the name carries no certificate at all. A refused connection is a server configuration question, not a certificate one, and it is reported as such.