Chainlook opens a real TLS connection, reads the certificate chain your server actually sends, and tells you — in plain language — when it expires, who issued it, every hostname it covers, and whether the chain is complete.
Verifies each certificate links to the next and the chain terminates at a trusted root — the failure that looks like a network problem on mobile.
Days remaining until the certificate expires, plus every Subject Alternative Name the certificate covers — no hidden domains.
Every certificate the server sent — subject, issuer, serial, and fingerprint — in order, so you can see exactly what a client receives.
Distinguishes timeout, DNS failure, refused connection, and Cloudflare blocking — never guesses or presents a platform limitation as a finding about your server.