See the certificate a domain presents on port 443: issuer, names, expiry, and whether it is trusted.
An SSL check opens a TLS connection to the domain and reads the certificate the server presents. It shows who issued it, which names it covers, when it expires, and whether the chain is trusted.
A name mismatch or an expired certificate will fail in browsers even when the site still answers. Check it before a certificate is due, and again after you install a new one.
The certificate chain verified for that hostname. An untrusted result includes the reason, such as expiry or a name mismatch.
Port 443 only. Mail and other services on other ports are not opened.
Enter a domain. The check follows the public address for that name and asks for a certificate in its name.