Certificate chain checker

See the certificates a server sends with its own, and whether the chain is right.

One-off check. Nothing is saved.

What the result shows

Complete

The intermediate that links your certificate to a trusted root is sent. Browsers often fetch a missing one themselves; curl, Java, Android apps and API clients don't.

In order

Your certificate first, then the one that issued it, and so on. When the order is wrong, the numbered list shows the order to send them in.

Nothing expired

No expired intermediate is still being sent; strict clients refuse it even when your own certificate is valid.

The table

Each certificate as sent: who it is for, who issued it, its key, and when it expires. A root at the end is optional.

It opens one connection to port 443 of the domain, only if it points to a public address, and stores nothing. The verdict is the same as for a monitored domain.