Certificate Inspector

This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.

Try:

About Certificate Inspector

The CSR.plus Certificate Inspector is a free certificate chain checker that performs a deeper health check on the SSL/TLS certificate served by a live host. It fetches the presented chain and evaluates validity windows, the signature algorithm, key strength, SAN coverage, and best-practice compliance, then summarises whether the certificate is trustworthy.

A regular SSL checker tells you a site "has a certificate"; the inspector tells you whether that certificate is actually healthy. It detects expired or not-yet-valid certificates, weak signature algorithms such as SHA-1, undersized keys, missing intermediate certificates, and hosts serving incomplete chains — the issues that break browsers and monitoring tools.

Why use

  • Analyse the full certificate chain served by a host, including intermediates
  • Flag expired, not-yet-valid, and SHA-1-signed certificates
  • Check key strength and SAN coverage against current best practices
  • Works for custom ports and non-standard TLS services

How to use

  1. Enter the hostname you want to inspect (for example example.com).
  2. Optionally set a custom port if the service is not on 443.
  3. The inspector performs a live TLS connection and analyses the presented certificate chain.
  4. Read the graded report covering validity, algorithm, key size, SAN, and best-practice warnings.

Frequently asked questions

▸Does it connect to the real server?

Yes. It performs a live TLS connection to read the certificate exactly as a visitor’s browser would.

▸What issues does it flag?

Expired or not-yet-valid certificates, weak signature algorithms, small key sizes, SAN mismatches, and missing intermediate certificates.

▸Can it inspect non-standard ports?

Yes. You can specify a custom port when the service does not use the default 443.

▸What is a certificate chain?

The chain is the ordered list of certificates from your leaf certificate up to a trusted root CA. Missing intermediates are the most common chain problem.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.