TLS & certificate chain checker

See whether a server sends its full certificate chain in the right order, which TLS versions it accepts (1.0, 1.1, 1.2, 1.3) and the cipher it picks for each, and whether it still allows weak ciphers. For the expiry date and trust, use the SSL certificate checker.

Takes a few seconds. One-off test, nothing is saved.

What the tool looks at

Chain order and completeness

A server should send its own certificate first, then the intermediate that issued it. A missing intermediate works in some browsers and fails in curl, Java, Android apps and API clients; a chain in the wrong order breaks some of those too.

TLS versions

TLS 1.0 and 1.1 are obsolete and should be off. TLS 1.2 is the baseline and TLS 1.3 is the current version. The tool tries each one and shows the cipher the server chooses.

Weak ciphers

It checks whether the server still accepts anonymous or NULL ciphers (no or broken protection), and whether TLS 1.2 uses a cipher without forward secrecy.

The tool opens a few short connections to port 443 of the domain, only to public addresses, and stores nothing. It looks at what a server offers, not at what is behind it: a load balancer or CDN may answer differently from the origin server. It does not list every cipher suite.