Getting started, frequently asked questions, and known limitations for the Chainlook TLS Certificate Chain Checker.
Paste a hostname. Chainlook opens a real TLS connection to that server, reads the certificate chain it actually presents, and reports — in plain language — the expiry date and days remaining, who issued it, every hostname the certificate covers, and whether the chain is complete from leaf to a trusted root.
To check a certificate:
No account needed. No sign-up. Each check is stateless — results are displayed in your browser and discarded when you leave the page.
A TLS certificate chain starts with your server's leaf certificate and links through one or more intermediate certificates to a trusted root. Some servers — especially those configured with older tools — send only the leaf certificate, omitting the intermediate CA certificate(s).
Browsers on desktop often work anyway because they cache intermediate certificates from previous visits. Mobile clients and fresh browser profiles do not have that cache. The result: your site loads fine for you, and it fails for someone visiting it for the first time on a phone. Chainlook flags this gap as an incomplete chain so you can fix it before it becomes an outage.
No. Chainlook accepts hostnames only — for example github.com, www.example.com, or api.stripe.com. IP addresses are not supported because the TLS connection verification and certificate Subject Alternative Name comparison are hostname-based.
There are a few common reasons:
No. Chainlook is a diagnostic tool — it answers when you ask it. There is no email sender, no alerting system, no daemon, and no scheduled re-check. The tool does not monitor, watch, or notify you about anything. If you need expiry monitoring, consider a dedicated certificate lifecycle management service — Chainlook is not one.
Not yet. An API is planned as part of the Pro tier, but it has not been built. Today the only interface is the web form on the App page.
No. The free tool accepts one hostname per check. Batch checks (up to 10 hostnames per run) are planned for the Pro tier, which is not yet available.
Chainlook distinguishes several failure modes so you can tell what actually went wrong:
Port 443 only. There is no way to specify a custom port. This is a limitation of the current implementation.
Chainlook is a focused diagnostic tool. Some features you might expect from a commercial TLS monitoring service are deliberately absent or not yet built. These are the current limitations:
Chainlook does not monitor certificates. It has no email sender, no cron-based re-check, no push notifications, and no dashboard. Every check is manual and stateless. If you need continuous monitoring, Chainlook is not the right tool for that use case.
Because Chainlook runs on Cloudflare Workers, it cannot open a TCP connection to another host behind Cloudflare. Targets behind Cloudflare will always be reported as unreachable. This is a platform limitation of the Workers runtime, not a finding about your server.
Every check targets port 443. Servers that serve HTTPS on a non-standard port cannot be checked.
You must enter a hostname. IPv4 and IPv6 addresses are not accepted.
Every check is independent. Check results are not saved, logged, or stored. There is no account system, no check history, and no way to review past results. If you reload the page, previous results are gone.
Batch checks, JSON/CSV exports, API access, and the Pro subscription plan are on the roadmap but have not been implemented. The Pro pricing page and checkout form are demonstrations only — no payment is processed and no subscriptions are created.
Chainlook is maintained by a small team. Support is handled through this Help Centre — the information on this page covers the most common questions and known issues.
Routine questions — If you cannot find an answer on this page, review the Terms of Service and Privacy Policy for further details about how the tool operates.
Feature requests & bug reports — These are reviewed periodically by the operator. There is no public issue tracker or support ticket system at this time.
Urgent / escalation — If you are experiencing a problem that suggests a security issue with the tool itself, or a matter requiring the operator's direct attention (e.g. takedown requests, legal notices), the issue will be escalated to the owner.
Escalation: owner-on-call — not for routine questions