Skip to content

SSL/TLS Certificate Checker

Check a public domain's HTTPS response, redirects, HSTS header, Certificate Transparency metadata, and DANE/TLSA signal.

Part of AppSec Santa's free website security scanners โ€” five browser-accessible tools, no signup.

HTTPS & Browser Policy Signals

Observe public HTTP and HTTPS responses, including the HSTS policy returned by the HTTPS endpoint.

  • HTTPS availability and response check
  • HTTP to HTTPS redirect verification
  • HSTS header parsing (max-age, includeSubDomains, preload token)
  • Direct HTTPS-to-HTTP redirect check
🔒
HTTPS
Public HTTPS response observed
HTTP Redirect
Direct HTTP response behavior
🛡
HSTS
Returned browser policy
Redirect Check
Flags a direct redirect to HTTP

Certificate Transparency Metadata

Review a matching Certificate Transparency entry. The data does not identify or validate the certificate presented by the live endpoint.

  • Validity dates from the selected CT entry
  • Entries returned by queried CT sources
  • Issuer metadata from the selected CT entry
  • Names listed in the selected CT entry
Example Results
HTTPS Available +15
HSTS Configuration +15
CT Certificate Dates Info
CT Issuer Metadata Info

Selected DNS and Redirect Signals

Check for TLSA records and the resolver's DNSSEC authentication signal. The checker does not compare TLSA association data with the live certificate.

  • DANE/TLSA DNS record detection
  • Resolver DNSSEC authentication signal
  • Direct HTTPS-to-HTTP redirect check
  • Unknown results kept separate from passes
CT Entry Details
; CT Entry Metadata
Issuer:     Let's Encrypt (R3)
Valid From: 2025-12-01
Valid To:   2026-03-01
Days Left:  21 days
CN:         example.com

; Names in CT Entry
example.com
*.example.com

; DANE/TLSA
No TLSA records found

Check Your Other Security Layers Too

SSL/TLS is one layer. HTTP security headers and DNS controls provide additional signals. These checks add configuration evidence but do not provide a complete security assessment.