SCANTIDE ONLINE
Scantide Online Guide

TLS Certificate Checklist for Public Websites

A valid certificate is only the beginning. Review expiry, hostname coverage, chain trust, redirects and whether every intended public endpoint consistently uses HTTPS.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: A valid certificate is only the beginning. Review expiry, hostname coverage, chain trust, redirects and whether every intended public endpoint consistently uses HTTPS.

Check the hostname

The certificate should cover the hostname users actually visit. Redirecting from one name to another does not fix a certificate mismatch on the first HTTPS connection.

Check expiry and chain trust

Expired certificates and broken chains create immediate trust failures. Automated renewal still needs monitoring because automation can fail.

Review redirects and HTTP behavior

A site may have a good HTTPS certificate while still serving content over HTTP or redirecting in unexpected ways.

Look at the surrounding TLS evidence

Scantide Online reviews public HTTPS/TLS and certificate evidence alongside headers, cookies and infrastructure so the certificate is not assessed in isolation.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: Website Privacy and Cookie Scanner

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Current Scantide source: DNS, SPF and DMARC Security Checker

IT administrators, security teams, consultants and technically minded users who need readable evidence about systems or websites they are authorized to review.

Field experience from the archive

Historical source · JufCorp: Anyone ideas? How to disable vompatibility check in Excel 2007?

Disbling compatibiliy check when opening 2003 .xls in @Office 2007 impossible. Gah. Comp-check f##%s it up in remote app when alt pg up don't work.

Historical source · JufCorp: Syspeace first public month - 40 000+ brute force attacks blocked!

So far,our first public month.40 000+ brute force attacks successfully blocked and traced! #rdp #windowsserver #infosec http://t.co/KOlgoMLO -- Syspeace (@Syspeace)

Historical source · JufCorp: Securing your servers, users and customers online

Remember to check your mail queues on a regular basis If you're starting to have loads of undelivered mail to and from various domains you could actually have a DNS server that's under attack , not being able to service your Exchange server with required information .

Practical review checklist

Frequently asked questions

Does a valid certificate mean a site is secure?

No. It means the TLS identity and encryption checks succeeded; application security is a separate question.

Why monitor certificates if renewal is automatic?

Because DNS, ACME challenges, account changes and deployment failures can still break automatic renewal.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides