What we check
- Validity period — how many days are left until expiry. We warn you two weeks in advance.
- Chain of trust — whether the server sends intermediate certificates and whether the chain leads to a root authority that browsers trust. A missing intermediate certificate is the most common cause of errors on phones.
- Domain match — whether the site name is among the certificate's domains (wildcards such as *.example.com included).
- Protocol and cipher — modern servers should use TLS 1.2 or 1.3.
We connect the same way a browser does, sending the domain name (SNI), so you see exactly the certificate your visitors get. You can also check a non-standard port — mail (465, 993, 995) or a control panel.
Need a certificate? Choose SSL at MEVCORE — from free Let’s Encrypt to organization-validated certificates.