WEB & TLS

SSL Certificate Inspector

View certificate names, issuer, validity dates, fingerprint and remaining lifetime.

39DMultiple locationsChoose the test server below

RUN TEST

SSL Certificate Inspector

Public targets only
Signed distributed testingRemote locations accept authenticated requests only.

HOW IT WORKS

About the SSL Certificate Inspector

The server opens a TLS connection using SNI, captures the peer certificate and parses its X.509 fields. The destination is validated as public before any socket is opened.

How to use this result

  1. Run the test from this server.Use a public hostname, address, prefix or ASN in the format requested above.
  2. Compare test locations.Choose another available 39D node or run a local command to identify location-specific behaviour.
  3. Correlate related evidence.Use the related tools below to compare DNS, routes, ports, TLS and application responses.
  4. Keep the time and context.Routing, DNS caches and reputation data change, so record when the result was collected.

Common interpretation issues

  • The certificate may differ when SNI is omitted, which is why the hostname is preserved.
  • An incomplete chain can affect some clients even when the leaf certificate looks correct.
  • Certificate validity does not prove that the web application itself is secure.

NEED HELP INTERPRETING THE RESULT?

39D supports business networks, cyber security and managed IT.

For ongoing support or a larger infrastructure project, speak to the 39D team.

Visit 39D

Frequently asked questions

Does this check automatic renewal?

It shows the current certificate only. Historical monitoring can alert you to approaching expiry when integrated with your own notification process.

What name must match?

The requested hostname should appear in the Subject Alternative Name extension.