TLSWatch

Learn

How to read results

TLSWatch opens a TLS connection to a public hostname (port 443 by default, or 8443) after SSRF checks, then reads the leaf certificate and presented chain. It does not crawl your site, prove absence of vulnerabilities, or certify compliance.

What you get

Finding statuses

What results are not

A valid, non-expired certificate that covers the hostname does not clear risk or prove policy alignment. TLSWatch avoids marketing outcome language.

Sharing

Reports use opaque high-entropy IDs at /r/:id. There is no public list of reports.

Inspect a hostname