Independent verification of your configuration.
WHAT THEY REPORT
Whether the certificate is valid and trusted Whether the chain is complete, including intermediates Which TLS versions and ciphers the server offers Configuration weaknesses, with a grade The expiry date Which hostnames are covered
WHY USE ONE
Your browser may have cached an intermediate, hiding a chain problem that affects other visitors. An external checker sees what a fresh client sees.
WHEN TO RUN ONE
After issuing a new certificate After a migration When a visitor reports an error you cannot reproduce As part of a periodic review
WHAT TO ACT ON
- An incomplete chain: reinstall including the intermediate bundle
- Expiry approaching with no renewal: investigate AutoSSL
- Obsolete protocols offered: raise with us, though our servers are configured correctly by default
WHAT TO IGNORE
Grades below the top mark are not necessarily a problem. Some deductions relate to configuration choices that trade compatibility against theoretical weaknesses.
Focus on validity, chain and expiry.