SSL errors: expiry, hostname and certificate chain
Find the cause before replacing your TLS configuration.
check.uk.app technical team · Reviewed 26 September 2026
What our result means
The TLS check attempts a verified connection to port 443 for the final HTTP hostname. Success confirms that this probe trusted the certificate at that moment. It is not a full cipher-suite or vulnerability audit.
Check the three common causes
Check the expiry date, the exact hostname and the certificate chain. A certificate for example.com does not automatically cover every subdomain. A browser may already have an intermediate certificate cached, so browser success alone is not enough.
Inspect without disabling verification
Replace example.com with your hostname. Keep certificate verification enabled; curl -k can hide the problem you are diagnosing.
curl -I --connect-timeout 5 --max-time 15 https://example.com/Fix and repeat
For a missing intermediate, configure the full certificate chain supplied by your issuer. For expiry, renew the certificate and confirm that the public endpoint serves it. If a proxy terminates TLS, inspect that proxy as well. Validate your server configuration before reloading, then repeat the external test.