SSL Certificate Checker
See who issued a site’s certificate, when it expires and which hostnames it covers.
Enter a URL to follow its redirects, list the response headers and grade the security headers browsers rely on. Useful for debugging caching, CORS, redirects and webhook endpoints.
| Header | Value |
|---|
SensaCat watches SSL certificates, domain registrations and credentials, and reminds your team well before anything expires.
At minimum: Strict-Transport-Security on HTTPS sites, a Content-Security-Policy, X-Content-Type-Options: nosniff, a frame-ancestors directive or X-Frame-Options, and a Referrer-Policy. Permissions-Policy is a good addition.
Strict-Transport-Security tells browsers to use HTTPS for your domain for a set time, so they never make a plain HTTP request that could be intercepted.
Redirects, missing HTTPS and unexpected authentication challenges are common reasons webhook deliveries fail. Checking the endpoint shows you what a sender sees.
Public http and https URLs on the standard ports 80 and 443. Private, local and internal network addresses are blocked.
See who issued a site’s certificate, when it expires and which hostnames it covers.
What each HTTP status code means, whether to retry it and whether it’s healthy.
Query A, AAAA, CNAME, MX, TXT, NS, CAA and SOA records over DNS-over-HTTPS.