Certificate Inspector FAQ
This page explains what the checker measures, how to interpret its examples, and where its conclusions stop. It is a practical guide for developers, operators, and site owners investigating public HTTPS services.
Short version: a scan is an external snapshot of one hostname and one connection path. It is useful evidence, but it is not a complete security audit or compliance certification.
- What does an A–F grade mean?
- The grade summarizes the findings visible to the scanner. A means no major finding was observed; B means a warning needs attention; C means a significant finding is present; D means multiple serious findings need remediation; F means fundamental checks are failing. The grade is a screening aid and should not replace an organization’s policy or risk review.
- Are the A–F examples real websites?
- No. The sample buttons are illustrative, built-in reports that demonstrate consistent outcomes such as expiration risk, hostname mismatch, weak cryptography, and a broken chain. They do not represent live scans and do not identify real organizations.
- What happens when I enter a hostname?
- The backend connects to the public HTTPS endpoint using the hostname for TLS server-name indication, then reports the certificate and negotiated connection data it can observe. The result applies to that endpoint and path at scan time.
- Can I enter a full URL?
- Enter a fully qualified hostname such as
example.com. The checker intentionally rejects URL paths, schemes, ports, localhost names, and other values that are not public hostnames. - What does uploading a certificate do?
- A PEM or DER certificate can be parsed locally in your browser. The selected file is not uploaded by the page. Local parsing can show fields such as subject, issuer, dates, SANs, key usage, and signature algorithm, but it cannot prove remote trust or negotiated TLS behavior.
- Does a current certificate prove that a site is secure?
- No. A certificate may be unexpired while the hostname is wrong, the chain is incomplete, the TLS policy is weak, or the private key is poorly protected. Review the findings together with service configuration and operational records.
- Does the post-quantum result certify quantum safety?
- No. The PQC section reports externally visible certificate and, when available, handshake signals. It cannot inventory internal keys, stored data, VPNs, HSMs, code-signing systems, or every client path. See the post-quantum readiness guide.
- How often should I scan?
- Scan after certificate issuance, deployment, proxy or DNS changes, and TLS-policy changes. For ongoing operations, pair endpoint checks with certificate inventory, renewal monitoring, and owner notification.
- Where can I read the grading details?
- The methodology page describes the evidence and limitations. The expiration, hostname, chain, and TLS guides explain common findings in more depth.
Last reviewed: October 2026. Standards, browser behavior, certificate-authority policy, and platform guidance change over time; confirm important decisions against current documentation.