What this SNI checker shows
When you run a check, HostChecker opens a TLS connection to port 443 of the address your hostname points to and sends the hostname as the Server Name Indication (SNI). It then reads the certificate the server answers with, repeats the handshake without any server name to find the default certificate, and sends one HTTP request over the first connection. Here is an example result, with what each part tells you:
Connection
Certificate for example.com
Without a server name
Servers that host many sites on one address use a default certificate for clients that send no name.
HTTP response
The HTTP request is made even when the certificate has a problem, so you see the status either way. The certificate problem is reported on its own line.
What SNI is
One IP address can serve thousands of HTTPS sites. When a browser connects, the server has to pick a certificate before any web request is sent, so it needs to know which site the visitor wants. The client puts the hostname in the first message of the TLS handshake, the ClientHello, in an extension called Server Name Indication. The server uses it to choose the certificate and, behind the scenes, the site. The HTTP Host header carries the same name, but it is sent inside the encrypted connection, too late to choose the certificate.
SNI is defined in RFC 6066, section 3. The name must be a fully qualified domain name: literal IPv4 and IPv6 addresses are not permitted, so a client that connects to a bare IP address sends no SNI at all. That is why this tool asks for a hostname, and takes an IP address only in the separate “Connect to” field.
In TLS 1.2 and in TLS 1.3 the SNI travels in clear text, so networks between the client and the server can read it. Encrypted Client Hello (RFC 9849, published March 2026) encrypts it when the client and server both support it. It needs TLS 1.3 and the server’s key published in a DNS HTTPS record. This checker sends a standard ClientHello and does not use ECH.
How to read the result
- Handshake completed, 200 OK. The server accepted the name, presented a certificate and answered the request. Check the certificate lines too: a 200 with “Wrong name” or “Not trusted” means the server answers, but a browser would show a warning.
- A redirect (301, 302, 307, 308). The server answered, and the page it sent you to is where the content lives. The redirect is not followed, so the result says nothing about the page at the end of it. To follow redirects and see each step, use Host Check.
- 403, 404 or another 4xx. The TLS connection worked and the web server refused or could not find the request. A 403 is common when a firewall or bot filter does not like automated requests.
- 5xx. The server or a proxy in front of it reported an error. For 502, 503 and 504 the problem is usually the application behind the proxy.
- Handshake failed with “unrecognized name”. The server sent the TLS alert
unrecognized_name(112). RFC 6066 lets a server either abort with that alert or carry on with a default site, and this one aborts. The address has no certificate or site configured for the name you sent. Add the name to the server’s configuration, or check that the name points at the right server. - Handshake failed with a handshake failure or a closed connection. The server refused the connection after the ClientHello. Common causes are no TLS version or cipher suite in common, a firewall that drops connections, and a server that is not ready for TLS on that address.
- Connection refused or timed out. Nothing is answering on port 443 at that address, or a firewall is dropping the traffic.
- Without SNI: a different certificate. The address serves several sites and falls back to a default certificate. This is normal on shared hosting, CDNs and load balancers.
- Without SNI: refused. The server needs a name to proceed. Some CDNs and proxies behave this way.
What people use an SNI check for
Testing a server before DNS points at it
Enter the hostname, and put the new server’s IPv4 address in “Connect to”. The check connects to that address and sends the hostname as the SNI and the Host header, so you see the certificate and the HTTP status that visitors would get after the DNS change. A certificate that does not cover the name, or a 404 from a default site, shows up here instead of after the switch.
Finding out why a certificate is wrong
When a browser reports a name mismatch on a host that serves many sites, the server is usually returning the default certificate because it did not match the name. Compare “Certificate for” with “Without a server name”. If they are the same, the server has no certificate for your name on that address.
Checking a CDN or load balancer
Providers that serve custom domains from shared addresses choose the site by SNI. A handshake failure or a default certificate after you added a domain usually means the provider has not finished setting it up, or the domain is not attached to the address you are testing.
What this check does not tell you
- It runs from HostChecker’s server, not from your network. It cannot show whether a host is reachable from your connection, or whether a mobile carrier or firewall treats it differently.
- Port 443 and IPv4 only. IPv6 addresses cannot be entered.
- One HTTP request for the home page, with the headers only. Redirects are not followed and no page content is read.
- The trust check uses the authorities this server trusts. A device with a different list can reach a different verdict.
- It does not audit the TLS setup. It reports the version and cipher suite that were agreed, and does not test older versions, weak ciphers, certificate revocation or Encrypted Client Hello.
- One hostname per check. See the FAQ for why.
Frequently asked questions
What is SNI?
Server Name Indication is a field in the first message of a TLS handshake where the client names the site it wants. It lets one IP address serve many HTTPS sites, each with its own certificate. It is defined in RFC 6066, section 3.
How do I check which certificate a server returns for a name?
Enter the name above. The “Certificate for” card shows what the server presented when it was sent that name. On your own machine, run openssl s_client -connect example.com:443 -servername example.com. Since OpenSSL 1.1.1, s_client sends the name given to -connect as the SNI when it is a hostname, so -servername matters when you connect to an IP address or want to send a different name. -noservername sends none and returns the default certificate.
How do I test a server before changing DNS?
Put the hostname in the first box and the new server’s IPv4 address in “Connect to”. The check sends the hostname as the SNI and the Host header to that address. The command-line equivalent is curl -I --resolve example.com:443:203.0.113.10 https://example.com/.
What does “unrecognized name” mean?
The server answered the handshake with the TLS alert unrecognized_name (code 112). The server has no site or certificate for the name you sent on that address. RFC 6066 allows a server to abort with this alert or to continue with a default site. Add the name to the server configuration, or send the request to the address that hosts it.
Why can’t I enter an IP address as the hostname?
RFC 6066 does not allow literal IPv4 or IPv6 addresses as an SNI name, so a TLS client never sends one. To test a name against a particular address, enter the name in the first box and the address in “Connect to”. To see the certificate an IP address serves by default, read the “Without a server name” card.
Why is the certificate without SNI different?
A server that hosts many sites chooses a certificate by name. With no name, it falls back to a default one, which usually belongs to the hosting provider or to one site on the server. A different default certificate is normal. Some servers refuse the handshake instead.
Does this show whether a host works from my network or mobile plan?
No. The check runs from HostChecker’s server, so it shows what that server sees. How your connection reaches a host, and how your network provider handles the traffic, can differ. Test from your own connection with openssl or curl.
Does the checker use Encrypted Client Hello?
No. It sends the server name in clear text, as most clients still do. Encrypted Client Hello (RFC 9849) encrypts the name when the client and server both support it.
Can I check a list of hosts?
No. Each check takes one hostname, and there is no bulk input or API. Connecting to many other people’s servers from this one is not something HostChecker offers. For lists, run openssl or curl from your own machine.
Is the SNI checker free, and is there a limit?
It is free, with no signup or account. To keep it fast for everyone, the number of checks that can run in a short time is limited. If you reach the limit, the result says how long to wait before trying again.
Can I check a port other than 443?
No. The checker connects to the standard HTTPS port only.