SSL/TLS & Website

Certificate trust and chain check

Whether browsers trust the certificate: issued by a real authority, served with its full chain, and not revoked.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We check that the certificate chains to a trusted authority, that the server sends the intermediate certificates, that it is not self-signed or not yet valid, and that it has not been revoked.

Why it matters to your business

A certificate can look fine in your own browser and fail for a customer's phone or an older computer, usually because an intermediate certificate is missing. Self-signed and revoked certificates produce the same full-page warning as an expired one.

How to fix it

  1. Install the full chain your certificate authority provides (often a "fullchain" or "bundle" file), not just the certificate.
  2. Replace self-signed certificates with one from a public authority such as Let's Encrypt.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.