SSL / TLS Checker: How It Works
An SSL/TLS check tells you whether a site's certificate is valid, who issued it, when it expires, and whether the chain is complete. Most certificate errors visitors encounter come from three causes, and all three are visible in a check like this.
What a certificate proves
A certificate binds a public key to a domain name, vouched for by a certificate authority the browser already trusts. It establishes that you are talking to the holder of that domain's private key, and it enables the encrypted connection.
What it does not prove is that the site is honest. A phishing site can obtain a valid certificate for its own domain in minutes. The padlock means 'this connection is private and the domain is what it claims' — not 'this site is trustworthy'.
The three common failures
| Error | Cause |
|---|---|
| Expired | Renewal missed — the most common outage of all |
| Name mismatch | Certificate covers example.com but not www.example.com |
| Incomplete chain | Intermediate certificate not installed on the server |
The incomplete chain is the most confusing, because it often works in one browser and fails in another. Some clients cache intermediates from previous visits to other sites and appear to succeed; others do not and fail. A site that 'works on my machine' but fails for users is very often this.
Validation levels
| Type | Verifies | Issued in |
|---|---|---|
| Domain Validated (DV) | Control of the domain | Minutes, usually free |
| Organisation Validated (OV) | Domain plus organisation identity | Days |
| Extended Validation (EV) | Extensive legal verification | Weeks |
Browsers stopped displaying special indicators for EV certificates several years ago, after research found users did not notice or act on them. Encryption strength is identical across all three; only the vetting differs. For most sites a free DV certificate is entirely appropriate.
Expiry and automation
Maximum certificate lifetimes have been shortened repeatedly and continue to fall. Manual renewal is no longer practical: automate issuance and renewal with ACME, and monitor expiry independently of the renewal process. Renewal at roughly two-thirds of the lifetime leaves room for a failure to be noticed and fixed before anything breaks.
What else to check
- Protocol versions. TLS 1.2 and 1.3 only; 1.0 and 1.1 are deprecated and should be disabled.
- HSTS. Instructs browsers to use HTTPS only, preventing downgrade attacks.
- Mixed content. A secure page loading images or scripts over HTTP undermines the whole connection.
- Redirects. HTTP should redirect to HTTPS with a permanent redirect, not serve content.
- SAN coverage. Confirm every hostname you serve is listed, including www and any subdomains.