Domain Security
SSL / TLS Certificate Checker & Expiry Monitor
Verify HTTPS SSL/TLS certificate chains, expiration dates, Certificate Authority (CA) issuers, Subject Alternative Names (SANs), and protocol support (TLS 1.2, TLS 1.3). SSL/TLS certificates establish encrypted connections and verify server identity. An expired, misconfigured, or untrusted certificate causes browser security warnings that immediately destroy user trust and prevent visitors from accessing your site. Avoid unexpected downtime with proactive certificate health checks.
Key Capabilities & Features
dnsfyi combines high-speed global Anycast DNS queries with comprehensive security auditing into a unified diagnostic suite.
- • Days remaining countdown and expiration alert indicators
- • Full certificate chain verification (Leaf, Intermediate, Root CA)
- • Subject Alternative Names (SAN) hostname coverage check
- • OCSP stapling and TLS protocol version validation
- • Cipher suite strength evaluation (weak vs modern)
- • Certificate transparency log verification
How to Use This Tool
To audit any domain or IP address, enter the hostname into the search box to run an instant parallel multi-resolver inspection.
- Enter a domain name or IP address to initiate a live TLS handshake.
- dnsfyi connects to your server on port 443 and retrieves the full certificate chain.
- Review the expiration countdown — certificates expiring within 30 days are flagged as warnings.
- Check the chain of trust: Leaf → Intermediate CA → Root CA must all be valid and trusted.
- Inspect SAN hostnames to confirm all required domains (www, subdomains) are covered by the certificate.
Common Use Cases
dnsfyi is primarily used to troubleshoot email deliverability failures, verify global DNS propagation, and audit SSL certificate health.
- → Monitoring certificate expiration to prevent unexpected HTTPS outages.
- → Verifying a new certificate is correctly installed and the full chain is served.
- → Diagnosing SSL handshake errors caused by missing intermediate CA certificates.
- → Checking if wildcard or SAN certificates cover all required subdomains.
- → Auditing TLS protocol version support to ensure TLS 1.0/1.1 are disabled.
Frequently Asked Questions
Find direct answers about dnsfyi's multi-resolver query engine, privacy policy, domain security checks, and free REST API.
- Why does my browser show a certificate warning even though the cert is valid?
- The most common reason is a missing intermediate certificate. Browsers require the full chain (Leaf → Intermediate → Root). If your server only serves the leaf certificate, some browsers will reject it. Use this tool to verify the complete chain is present.
- What is an SSL SAN certificate?
- A Subject Alternative Name (SAN) certificate can secure multiple domain names with a single certificate. For example, a single SAN cert can cover example.com, www.example.com, and api.example.com. Modern browsers require the domain to be listed in the SANs — the legacy Common Name (CN) field is no longer sufficient.
- How often should I renew my SSL certificate?
- Certificate validity periods are now capped at 398 days by browser requirements. Let's Encrypt certificates expire every 90 days and should be renewed automatically. Commercial DV/OV/EV certificates last up to 1 year. Set up monitoring to alert you at 30 days before expiry.
- What is OCSP stapling?
- OCSP (Online Certificate Status Protocol) stapling allows the web server to proactively fetch and cache the certificate revocation status from the CA, then include it in the TLS handshake. This eliminates the need for browsers to make a separate OCSP request, improving performance and privacy.
- What is the difference between DV, OV, and EV certificates?
- DV (Domain Validated): cheapest, only proves domain ownership, issued in minutes. OV (Organization Validated): proves the organization is legitimate, requires manual vetting. EV (Extended Validation): highest level of vetting, formerly showed the green bar in browsers (now replaced with a padlock icon in modern browsers).
- Why is TLS 1.0 and 1.1 dangerous?
- TLS 1.0 and 1.1 have known vulnerabilities (POODLE, BEAST, CRIME) and use deprecated cipher suites. All major browsers dropped support in 2020. Your server should only support TLS 1.2 and TLS 1.3.