SSL/TLS Certificate Checker
Check a public domain's HTTPS response, redirects, HSTS header, Certificate Transparency metadata, and DANE/TLSA signal.
Part of AppSec Santa's free website security scanners โ five browser-accessible tools, no signup.
HTTPS & Browser Policy Signals
Observe public HTTP and HTTPS responses, including the HSTS policy returned by the HTTPS endpoint.
- HTTPS availability and response check
- HTTP to HTTPS redirect verification
- HSTS header parsing (max-age, includeSubDomains, preload token)
- Direct HTTPS-to-HTTP redirect check
Certificate Transparency Metadata
Review a matching Certificate Transparency entry. The data does not identify or validate the certificate presented by the live endpoint.
- Validity dates from the selected CT entry
- Entries returned by queried CT sources
- Issuer metadata from the selected CT entry
- Names listed in the selected CT entry
Selected DNS and Redirect Signals
Check for TLSA records and the resolver's DNSSEC authentication signal. The checker does not compare TLSA association data with the live certificate.
- DANE/TLSA DNS record detection
- Resolver DNSSEC authentication signal
- Direct HTTPS-to-HTTP redirect check
- Unknown results kept separate from passes
; CT Entry Metadata Issuer: Let's Encrypt (R3) Valid From: 2025-12-01 Valid To: 2026-03-01 Days Left: 21 days CN: example.com ; Names in CT Entry example.com *.example.com ; DANE/TLSA No TLSA records found
HTTPS Configuration Check: โ
| Test | Score | Reason |
|---|
Check Your Other Security Layers Too
SSL/TLS is one layer. HTTP security headers and DNS controls provide additional signals. These checks add configuration evidence but do not provide a complete security assessment.