Certificate trust, per platform version

Your certificate works.
On whose device?

iOS 5 and iOS 26 ship completely different root stores. So do Android 4.4 and Android 16. We verify your certificate chain against the real trust anchors of 78 platform versions — and tell you exactly where it breaks, why, and how to fix it.

Free, no account needed · 5 checks a day (10 with a free account) · nothing stored for anonymous checks

78
Platform trust stores, rebuilt from official sources
5
Platform families — iOS · Android · webOS · Tizen · Fire OS
1,061
Root certificates fingerprinted and version-mapped
<30s
Full-chain verification across every store
How it works

Three steps. No agent, no install.

Everything runs against real, version-pinned trust stores — not a generic "system" bundle.

01

Point us at a domain, or paste a certificate

We open a TLS handshake, pull your full chain — leaf, intermediates, cross-signs — and fingerprint every certificate. Prefer not to expose a hostname? Paste the PEM directly.

$ chain for your-domain.com
leaf    CN=your-domain.com
inter  CN=R11, O=Let's Encrypt
root   CN=ISRG Root X1
02

We verify against real trust stores

Each store is rebuilt from the vendor's official root list — Apple's published iOS trust stores, Android AOSP, LG webOS, Samsung Tizen, Amazon Fire OS. A chain that passes on iOS 26 but fails on iOS 9 is reported as exactly that.

iOS 21 stores · 5 → 26Android 25 stores · 2.3 → 16webOS 28 stores · 3.0 → 4.0Tizen 3 storesFire OS 1 store
03

You get causes and fixes, not openssl output

Failures are grouped by root cause — "ISRG Root X1 is not in the iOS 9 trust store" — with the affected versions listed and a concrete fix, like which CA to switch to.

Root cause

ISRG Root X1 was added in iOS 10 and Android 7.1. Older versions reject the chain.

Fix: serve the full chain, or re-issue via a CA rooted since the versions you need.

Why not SSL Labs?

"Good certificate" ≠ "trusted by your users"

Graders tell you whether a certificate is configured well. We tell you whether the devices your users actually carry will accept it — version by version.

See a real report
SSL LabsPlatform Cert Check
Per-version trust stores78
iOS 5 → 26, Android 2.3 → 16Simulated partialReal root stores
webOS / Tizen / Fire OS coverageYes
Failures grouped by root causeRaw outputYes
Apple Ask / Blocked trust levelsYes
Expiry monitoring & re-check alertsPro
API for CI/CD gatesYesYes

Find out before your users do.

Run a free check in under thirty seconds. Upgrade when you want monitoring, alerts and an API — $9 a month, cancel anytime.