Certificate lookup
Check TLS certificates without a terminal
See who issued a site’s certificate, which names it covers (SANs), when it expires, and which TLS version the server negotiated with us. Useful before renewals and when debugging browser warnings.
Results reflect the certificate presented to our server at the moment of the request. CDNs and multi-SAN certs are common — the SAN list is the authoritative set of names, not just the common name.
Frequently asked questions
Does this work for localhost or private IPs?
No. Only public hostnames and public IPs are accepted, to prevent SSRF.
Which port is checked?
Port 443 only. This is not a general TLS scanner.
What if the certificate fails verification?
We still try to show subject, issuer, SANs, and dates, and flag the verification error.
Is the certificate stored?
No. The lookup is live and the response is not stored by this tool.