Paste a hostname.
See the whole chain.

Chainlook opens a real TLS connection, reads the certificate chain your server actually sends, and tells you — in plain language — when it expires, who issued it, every hostname it covers, and whether the chain is complete.

Check a certificate See plans

What you get

Chain completeness check

Verifies each certificate links to the next and the chain terminates at a trusted root — the failure that looks like a network problem on mobile.

Expiry & coverage

Days remaining until the certificate expires, plus every Subject Alternative Name the certificate covers — no hidden domains.

Full chain structure

Every certificate the server sent — subject, issuer, serial, and fingerprint — in order, so you can see exactly what a client receives.

Honest error reporting

Distinguishes timeout, DNS failure, refused connection, and Cloudflare blocking — never guesses or presents a platform limitation as a finding about your server.