Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A TLS checker tells you whether a hostname presents a usable certificate and how that server negotiates encrypted connections. Start by checking the exact hostname, certificate dates, subject/SAN coverage and intermediate chain. Then use a deeper public-server assessment for protocol, cipher and revocation details. For private or internal names, test from inside the network with OpenSSL because public scanners cannot reach them.

What a TLS checker actually verifies

HTTPS loading in one browser is only a partial signal. A checker connects to a specific hostname and port and reports what that endpoint presents during the TLS handshake. Depending on the tool, it can identify:

  • Whether a certificate is installed and served.
  • Whether the certificate covers the hostname you entered, including the relevant Subject Alternative Name (SAN).
  • Whether the certificate is expired or approaching expiration.
  • Whether the server sends the intermediate certificates needed to build a trusted chain.
  • Some certificate problems, such as outdated hash algorithms.
  • For deeper assessments, enabled TLS versions, cipher suites and revocation information.

The result applies to the tested hostname, port, network path and test vantage point. A certificate that works for www.example.com does not automatically prove that api.example.com, a separate IPv6 front end or a different load balancer is configured correctly.

Choose the right kind of check

Question Best test What it can and cannot tell you
Is the certificate installed, current and issued for this hostname? Basic certificate checker Reports presence, hostname coverage, expiration and chain/intermediate problems.
Which TLS protocols and ciphers are enabled? Detailed public-server assessment such as Qualys SSL Labs Examines effective public TLS configuration, including protocol and cipher behavior; it is not an exploit or application-vulnerability scan.
Can an internal or staging endpoint complete a handshake? OpenSSL from a machine that can reach it Shows the connection and certificate handshake locally. It does not, by itself, enumerate every protocol, cipher, hostname or browser trust condition.

SSL Shopper directs readers to SSL Labs when they need protocol, cipher or revocation information. Qualys describes SSL Labs as a non-commercial effort focused on public-server SSL configuration and states, “We never test for exploits.” Treat a strong TLS grade as evidence about TLS configuration, not proof that the web application is free of vulnerabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to check a public SSL certificate

  1. Enter the exact public hostname

    Use the name visitors actually type, including a subdomain such as www, shop or api. Test additional hostnames and front ends separately when they terminate TLS independently. Use the HTTPS port unless your service deliberately uses another port.

  2. Read identity and validity results

    Confirm that the certificate’s SAN list contains the exact hostname. Check the not-before and expiration dates using the current date and time of the checker. An expired certificate can produce browser errors even when the server is otherwise reachable.

  3. Inspect the chain

    The server normally sends its leaf certificate plus the intermediate certificates that connect it to a trusted root. A missing or incorrect intermediate can work for one client with a cached chain and fail for another. Install the complete chain at the TLS termination point rather than uploading a root certificate unnecessarily.

  4. Review warnings, not only the headline

    Look for hostname mismatch, expiration, incomplete installation and certificate-signature or hash warnings. Do not treat a green label as a universal security guarantee; it only reflects the checks that tool performed.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  5. Recheck after changing configuration

    Some public checker results can be cached for up to one day on repeated checks. An immediate repeat may therefore show the previous certificate. Record the hostname, port and check time, then allow for cache behavior before concluding that a deployment failed.

Checking TLS versions, ciphers and revocation

A basic certificate result does not answer which protocol versions the server accepts. Use a detailed public TLS assessment when you need protocol, cipher and revocation reporting. Such a test is useful for finding obsolete protocol support, weak cipher choices, certificate-chain issues and compatibility problems across clients.

TLS 1.3 compatibility is more than certificate existence

RFC 8446 specifies TLS 1.3. During the handshake, the server certificate’s public key and associated restrictions must be compatible with the authentication algorithm selected by the peers. The certificate is X.509v3 unless another certificate type is negotiated. Consequently, a certificate can be present and unexpired while a particular client still cannot complete a compatible handshake.

Do not copy old cipher recipes blindly

Protocol and cipher recommendations change as standards and software evolve. Verify settings against the current documentation for your web server, load balancer or CDN and the current CA/Browser Forum Baseline Requirements for publicly trusted certificates. An old configuration snippet is not a current compliance statement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Testing an internal hostname with OpenSSL

Public checkers cannot assess names that exist only on a private network. SSL Shopper gives this local connection example:

openssl s_client -connect hostname.example:443

Run it from a host that can resolve and reach the service. The output includes the negotiated connection and certificates presented by the server. Replace the hostname with the internal name and use the actual port if it is not 443.

This command is a diagnostic connection, not a complete audit. It does not automatically test every hostname on a shared server, enumerate all protocol versions or ciphers, validate every browser’s trust store, or perform revocation and exploit testing. For SNI-dependent services, connect with the intended name so the server selects the correct certificate:

openssl s_client -connect 10.0.0.25:443 -servername app.internal.example

Never send a private key to a checker. Private keys should remain on the server or in the system that terminates TLS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where a failed check is usually fixed

A checker observes the certificate and handshake at the TLS termination point. Depending on your architecture, that may be the web server, reverse proxy, load balancer or CDN rather than the application process. Confirm which component owns the public listener, update its certificate and intermediate-chain configuration, reload it safely, and then test each affected hostname.

Hostname mismatch

Issue or select a certificate whose SAN contains the exact requested name. A wildcard covers only one label (for example, *.example.com does not cover example.com or a.b.example.com).

Expired or not-yet-valid certificate

Install the renewed certificate and verify the server clock. Ensure the new certificate is deployed to every TLS termination point, not only one node.

Missing intermediate

Configure the server with the leaf certificate and required intermediate chain in the order expected by your server software. Do not assume clients will fetch a missing intermediate.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Unexpected certificate after deployment

Check DNS, IPv4 and IPv6 answers, CDN or load-balancer mappings and SNI configuration. Test each public hostname and address path separately.

Or skip the browser setup

If your goal is to capture a visual record of a public HTTPS page after checking it, ScreenshotNeo provides a single-call website screenshot API. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Only clean shots are billed: bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and responses identify the outcome with X-Page-Verdict and X-Billed headers. Its MCP server supplies take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

For API parameters and the complete option list, see ScreenshotNeo’s documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo’s Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting a TLS-checker result

The checker says the hostname is unsupported

The name is probably internal, private or not publicly resolvable. Run OpenSSL from inside the network, or publish the endpoint only if your security policy allows external testing.

The browser works but the checker reports a chain error

Your browser or operating system may have cached or separately downloaded an intermediate. Configure the server to send the complete chain and test from another client.

The result still shows the old certificate

Check for result caching, DNS differences and multiple termination points. SSL Shopper notes that repeated results may be cached for up to one day.

TLS 1.3 fails for one client

Compare the client’s supported authentication algorithms and certificate-key type with the server certificate and TLS 1.3 requirements. A valid certificate alone does not guarantee compatibility.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A high TLS score did not find an application problem

That is expected. SSL Labs assesses effective public TLS configuration and explicitly does not test for exploits. Use a separate, authorized application-security process for vulnerability testing.

Operational checklist

  • Test every public hostname, relevant port and independently configured front end.
  • Record the test date, hostname, port and whether the test was remote or local.
  • Verify SAN coverage, expiration and the complete intermediate chain.
  • Use a deep assessment for protocol, cipher and revocation questions.
  • Use OpenSSL for private endpoints from a reachable internal machine.
  • Re-test after cache windows, DNS changes and certificate deployment.
  • Review current standards and vendor documentation before changing protocol or cipher settings.

Frequently asked questions

Does a TLS checker prove my website is secure?

No. It verifies selected certificate and TLS properties. It does not establish that the application has no vulnerabilities, malware or authorization flaws.

Can I check a certificate without exposing a private server?

Yes. Use a client-side OpenSSL connection from a machine that can reach the private hostname; public services cannot test an endpoint they cannot access.

Should I test the root domain and the www hostname separately?

Yes, unless you have verified that both names resolve to the same TLS termination and certificate configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

How often should I run a TLS check?

Run it after every certificate, DNS, proxy, CDN or protocol change, and schedule recurring checks before the certificate expiration window so deployment problems are found before clients see them.

What information should I save from a TLS assessment?

Keep the hostname, port, test location, timestamp, certificate expiration, chain findings and protocol/cipher results so a later comparison distinguishes a real change from a cached result.

The Bottom Line

Verify certificate identity, dates and intermediates first; use a deeper public assessment for protocols and ciphers, and OpenSSL for private endpoints. A clean TLS result describes configuration, not the security of the entire application.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.