What the server sends. What your machine believes.
A free Windows app that inspects any TLS/SSL certificate and tells you whether this machine trusts it — and if not, exactly why.
Download for Windows7f2a696ac0764777524b3f5b277908729b9f301f91f484202df6180cc8de0638
7b506945434b53d24b1fd2be9a1b6bd368468353cad606663d25bace59aedfee
Fetches the live certificate over TLS (with SNI) and gives a plain green / amber / red verdict: trusted, trusted-but-flawed, or unknown to this machine.
Walks the full certificate chain to its root and shows exactly which store on this machine anchors the trust — or where the chain breaks.
When the same certificate also lives in a local Windows store, view both side by side with every difference and expiry highlighted.
Checks each Subject Alternative Name, resolving it from this machine and flagging short, unqualified names that only work on internal networks.
Load a .cer / .crt / .pem from disk, export the fetched certificate, or generate a printable, machine-stamped HTML report.
Everything runs on your machine against your own trust stores. Optional online revocation checking is the only step that touches the network — and only when you ask.