How to read results
TLSWatch opens a TLS connection to a public hostname (port 443 by default, or 8443) after SSRF checks, then reads the leaf certificate and presented chain. It does not crawl your site, prove absence of vulnerabilities, or certify compliance.
What you get
- Subject / issuer fields, SANs, notBefore / notAfter
- Days-to-expiry countdown and an informational urgency band
- Chain depth and self-signed / hostname-mismatch flags
- Negotiated protocol and cipher when the stack exposes them
Finding statuses
- pass — expected educational signal present
- warn — short window, self-signed, or soft gap
- fail — expired leaf or hostname mismatch
- info — protocol/cipher observation
What results are not
A valid, non-expired certificate that covers the hostname does not clear risk or prove policy alignment. TLSWatch avoids marketing outcome language.
Sharing
Reports use opaque high-entropy IDs at /r/:id. There is no public list of reports.