Is your site’s certificate about to expire? Does it cover www as well as the bare domain? Is the server sending the intermediate certificate? Safari on iPhone only shows a padlock. The SSL Certificate Checker in HTTPS Capture connects to any server and gives you the full report on your phone.
Run a check
- Open the Toolbox tab and choose SSL Certificate Checker.
- Enter a host such as
example.com. You can also enterhost:port(for examplemail.example.com:993) or paste a full URL. The default port is 443. - Tap Check Certificate.
The checker connects to the server directly and reads what it presents. It does not need capture to be running.
Read the verdict
At the top you’ll see one of these:
- Certificate is valid: trusted, in date, and covering the host you entered.
- Certificate works with warnings: for example, it expires soon.
- Certificate has problems: for example, it has expired, is not valid yet, the chain is not trusted, or the certificate does not cover the host you entered.
The expiry line tells you how much time is left, such as “Expires in 23 days”, or how long ago it expired.
What the report includes
- Handshake: the negotiated TLS version and cipher suite.
- Chain Trust: whether iOS trusts the full chain.
- Certificate Chain: the leaf first, then intermediates and the root. Each certificate shows its Common Name, Issued By, Not Before / Not After, public key algorithm and key size (or curve), extensions, and fingerprints you can copy.
- Names covered: every Subject Alternative Name, with the names that match your host highlighted.
Recent Checks keeps your latest hosts, so you can re-check your own domains with one tap.
Common findings and fixes
- Chain is not trusted while the browser on your computer is fine: the server is probably missing the intermediate certificate. Configure the full chain (
fullchain.pem) on the server. - Does not cover the host: the certificate lacks
www.or a subdomain. Reissue it with all the names you serve. - Expires soon: renew it, and check that automatic renewal (for example Let’s Encrypt with certbot) is really running.
- Old TLS version: if the handshake shows TLS 1.0 or 1.1, update the server configuration. Modern clients expect TLS 1.2 or 1.3.
More network tools in the Toolbox
The same Toolbox includes a JWT decoder, timestamp converter, Base64 and URL encoders, hash generator, JSON formatter, regex tester and more. They all run offline on the device.
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store