Enter a domain name to fetch and verify its live SSL certificate chain. A broken chain is one of the most common causes of browser SSL warnings even after a successful installation.
An SSL certificate is not trusted on its own — browsers trust it by following a chain: your leaf certificate → one or more intermediate CAs → a root CA that is embedded in the browser or operating system. If any link is missing, browsers show a warning.
The most common reason is a missing intermediate certificate. Many servers only serve the leaf certificate and omit the intermediate. You need to install the full chain file provided by your CA.
Root CAs are self-signed and embedded in browsers. Intermediates are signed by roots and used for day-to-day issuance. Using intermediates protects root keys — if an intermediate is compromised, it can be revoked without replacing the root.
Browse all SSL certificate types and find the right one for your site.
Take the SSL wizard →