Public TLS diagnosis

SSL and website health checker

Check public DNS, TLS validity, certificate names and expiry, HTTPS response and the HTTP-to-HTTPS behaviour of a domain.

Public IP onlyPrivate and reserved targets are blocked
Ports 80 / 443Fixed web-health scope
No redirect crawlOne direct response per protocol

A URL is accepted, but the checker uses only its public hostname.

Enter a public domain to inspect its HTTPS certificate and web response.

Safety and scope

A fixed web check, not an open proxy.

The server resolves the domain first and rejects private, loopback and reserved addresses. It connects only to ports 80 and 443, does not follow redirects and uses the domain as the TLS server name.

A valid certificate proves identity for the checked hostname at that moment. It does not prove that the application itself is secure.

  • DNS must resolve to a public address
  • TLS hostname verification is enabled
  • Certificate SAN names and expiry are shown
  • HTTP redirect target is reported but not followed
  • Checks time out and are rate-limited

Certificate valid but the site still fails?

Send the result together with the exact browser error and affected URL path.

Request diagnosis