What the server sends. What your machine believes.
A free Windows app that inspects any TLS/SSL certificate and tells you whether this machine trusts it — and if not, exactly why.
Download for Windows6dd558966bba571464df6a0a30f3817ed466b97a8dd55ca66fd3c18e447d48c0
6b61b78f77466b80f897fb3c31e952847b27e21ad018007bb94d1d1a892c4e60
Fetches the live certificate over TLS (with SNI) and gives a plain green / amber / red verdict: trusted, trusted-but-flawed, or unknown to this machine.
Walks the full certificate chain to its root and shows exactly which store on this machine anchors the trust — or where the chain breaks.
When the same certificate also lives in a local Windows store, view both side by side with every difference and expiry highlighted.
Checks each Subject Alternative Name, resolving it from this machine and flagging short, unqualified names that only work on internal networks.
Load a .cer / .crt / .pem from disk, export the fetched certificate, or generate a printable, machine-stamped HTML report.
Everything runs on your machine against your own trust stores. Optional online revocation checking is the only step that touches the network — and only when you ask.