LIVE TLS DIAGNOSTICS

Read the certificate behind a secure website.

Check hostname coverage, trust, expiry, issuer, protocol and cipher—then understand what each result means.

Port 443 only. Private, reserved and LAN destinations are blocked.

Certificate handshakeTrust and hostname matchValidity and renewal windowTLS protocol and cipher
Ready to inspect a public HTTPS hostname.Connection: AIOTEC server → target:443
READ THE HANDSHAKE

What this inspection tells you

TRUST

Certificate authority

A trusted chain connects the site certificate to a certificate authority recognized by the inspecting system.

NAME

Hostname coverage

The requested hostname must match a certificate subject alternative name, including valid wildcard coverage.

TIME

Validity window

Certificates work only between their start and expiry dates. Renewal should happen well before expiry.

TLS

Negotiated security

The protocol and cipher describe the encrypted connection negotiated for this specific inspection.

Safety boundary

AIOTEC connects only to public destinations on TCP port 443. Private, reserved and LAN addresses are rejected.

This is a point-in-time observation from the AIOTEC server. It is not a complete vulnerability scan, compliance certification or guarantee.