Check SSL certificate
check_sslRead-onlyIdempotent
Check the HTTPS certificate and TLS setup of a domain on port 443: issuer, expiry date and days left, whether the chain is complete and trusted, whether the certificate matches the name, key type and size, which TLS versions (1.0 to 1.3) the server accepts, and the CAA record that limits who may issue certificates. Checks www as well when given a bare domain. Every finding has a severity, a fix and a citation.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| detail | No | "summary" (default) lists only findings that need action; "full" also lists every passing check. | summary |
| domain | Yes | The domain to check, such as example.com. A website address (https://www.example.com/page) or an email address (jo@example.com) also works; the domain is taken from it. | |
| include_www | No | Also check www.<domain> when a bare domain is given and www exists. Default true. |