About this tool
Enter a domain to see the certificate the server currently presents: subject, issuer, validity dates, days remaining, and every domain it covers through subject alternative names. SAN is where problems usually hide — whether a certificate applies to a name depends on the SAN list, not the common name, so confirm every name you actually serve, including www and each subdomain. Days remaining is what you plan renewals against: automated renewal normally starts around 30 days before expiry, so a value that stays below that means renewal is not running. Chain validation is off by design, because a checker that refused to display a broken certificate could not help you diagnose one; being able to read a certificate here does not mean it is valid.