How the analysis works
A live hostname scan is restricted to a public HTTPS endpoint on TCP port 443. The scanner validates destination addresses, uses SNI, verifies the TLS connection, and summarizes certificate and handshake information.
- Certificate identity, issuer, serial, validity dates, SAN coverage, signature algorithm, and public-key details.
- Negotiated TLS version and cipher suite when the endpoint provides them.
- Findings for expiration, hostname mismatch, weak cryptography, and trust-path concerns.
- A distinction between a live backend scan and a local browser parse, which cannot establish remote trust or handshake state.
Results are not a complete vulnerability scan, compliance certification, or guarantee of future availability. Confirm important findings with the service owner and current certificate-management records.