The OriginalHostChecker

SNI Checker

Enter a hostname to send it as the SNI server name. You get the TLS handshake result, the certificate the server presents for that name, and the HTTP status. Free, no signup.

Try

What this SNI checker shows

When you run a check, HostChecker opens a TLS connection to port 443 of the address your hostname points to and sends the hostname as the Server Name Indication (SNI). It then reads the certificate the server answers with, repeats the handshake without any server name to find the default certificate, and sends one HTTP request over the first connection. Here is an example result, with what each part tells you:

Example What a check of example.com could show. Not a live result.
TLS handshake
OK
TLSv1.3
HTTP status
200
OK, from HEAD /
Certificate
Trusted
52 days left
Without SNI
Differs
certificate with no name

Connection

Server name sent
example.comThe name placed in the ClientHello. The server uses it to choose a certificate and a site.
Connected to
203.0.113.10 (from DNS)The address used. Type one into “Connect to” to test a different server with the same name.
Port
443Always the standard HTTPS port.
TLS version
TLSv1.3The version this checker and the server agreed on.
Cipher suite
TLS_AES_256_GCM_SHA384The encryption the connection uses.
Handshake time
16 msHow long the TLS setup took, after the TCP connection.
First byte
48 msTime until the first byte of the HTTP response arrived.

Certificate for example.com

Issued to
example.comThe certificate’s subject.
Names it covers
example.com *.example.comEvery name the certificate is valid for. The server name you sent has to match one of them.
Covers example.com
YesWhether the name you sent matches the list above, including wildcards.
Issued by
Example Trust ServicesThe certificate authority that signed it.
Valid from
2026-09-26The first day the certificate is valid.
Valid to
2026-12-25The last day the certificate is valid.
Trust check
Trusted, and the name matchesWhether the chain leads to an authority this server trusts. A failure names the problem.

Without a server name

Result
A different certificate from the one served for example.comWhat the address presents when a client sends no SNI. “Refused” means the server will not complete a handshake without a name.
Issued to
default.example.netWhose certificate that default is.

Servers that host many sites on one address use a default certificate for clients that send no name.

HTTP response

Status
200 OKThe status line of the response. A redirect (301, 302) is shown, and not followed.
Redirects to
noneThe Location header, when the status is a redirect.
Server header
cloudflareWhat the server says it is, when it says.
Protocol
HTTP/2The HTTP version that was used.
Request
HEAD https://example.com/A HEAD request for the home page. GET is used when the server does not support HEAD.

The HTTP request is made even when the certificate has a problem, so you see the status either way. The certificate problem is reported on its own line.

What SNI is

One IP address can serve thousands of HTTPS sites. When a browser connects, the server has to pick a certificate before any web request is sent, so it needs to know which site the visitor wants. The client puts the hostname in the first message of the TLS handshake, the ClientHello, in an extension called Server Name Indication. The server uses it to choose the certificate and, behind the scenes, the site. The HTTP Host header carries the same name, but it is sent inside the encrypted connection, too late to choose the certificate.

SNI is defined in RFC 6066, section 3. The name must be a fully qualified domain name: literal IPv4 and IPv6 addresses are not permitted, so a client that connects to a bare IP address sends no SNI at all. That is why this tool asks for a hostname, and takes an IP address only in the separate “Connect to” field.

In TLS 1.2 and in TLS 1.3 the SNI travels in clear text, so networks between the client and the server can read it. Encrypted Client Hello (RFC 9849, published March 2026) encrypts it when the client and server both support it. It needs TLS 1.3 and the server’s key published in a DNS HTTPS record. This checker sends a standard ClientHello and does not use ECH.

How to read the result

What people use an SNI check for

Testing a server before DNS points at it

Enter the hostname, and put the new server’s IPv4 address in “Connect to”. The check connects to that address and sends the hostname as the SNI and the Host header, so you see the certificate and the HTTP status that visitors would get after the DNS change. A certificate that does not cover the name, or a 404 from a default site, shows up here instead of after the switch.

Finding out why a certificate is wrong

When a browser reports a name mismatch on a host that serves many sites, the server is usually returning the default certificate because it did not match the name. Compare “Certificate for” with “Without a server name”. If they are the same, the server has no certificate for your name on that address.

Checking a CDN or load balancer

Providers that serve custom domains from shared addresses choose the site by SNI. A handshake failure or a default certificate after you added a domain usually means the provider has not finished setting it up, or the domain is not attached to the address you are testing.

What this check does not tell you

Frequently asked questions

What is SNI?

Server Name Indication is a field in the first message of a TLS handshake where the client names the site it wants. It lets one IP address serve many HTTPS sites, each with its own certificate. It is defined in RFC 6066, section 3.

How do I check which certificate a server returns for a name?

Enter the name above. The “Certificate for” card shows what the server presented when it was sent that name. On your own machine, run openssl s_client -connect example.com:443 -servername example.com. Since OpenSSL 1.1.1, s_client sends the name given to -connect as the SNI when it is a hostname, so -servername matters when you connect to an IP address or want to send a different name. -noservername sends none and returns the default certificate.

How do I test a server before changing DNS?

Put the hostname in the first box and the new server’s IPv4 address in “Connect to”. The check sends the hostname as the SNI and the Host header to that address. The command-line equivalent is curl -I --resolve example.com:443:203.0.113.10 https://example.com/.

What does “unrecognized name” mean?

The server answered the handshake with the TLS alert unrecognized_name (code 112). The server has no site or certificate for the name you sent on that address. RFC 6066 allows a server to abort with this alert or to continue with a default site. Add the name to the server configuration, or send the request to the address that hosts it.

Why can’t I enter an IP address as the hostname?

RFC 6066 does not allow literal IPv4 or IPv6 addresses as an SNI name, so a TLS client never sends one. To test a name against a particular address, enter the name in the first box and the address in “Connect to”. To see the certificate an IP address serves by default, read the “Without a server name” card.

Why is the certificate without SNI different?

A server that hosts many sites chooses a certificate by name. With no name, it falls back to a default one, which usually belongs to the hosting provider or to one site on the server. A different default certificate is normal. Some servers refuse the handshake instead.

Does this show whether a host works from my network or mobile plan?

No. The check runs from HostChecker’s server, so it shows what that server sees. How your connection reaches a host, and how your network provider handles the traffic, can differ. Test from your own connection with openssl or curl.

Does the checker use Encrypted Client Hello?

No. It sends the server name in clear text, as most clients still do. Encrypted Client Hello (RFC 9849) encrypts the name when the client and server both support it.

Can I check a list of hosts?

No. Each check takes one hostname, and there is no bulk input or API. Connecting to many other people’s servers from this one is not something HostChecker offers. For lists, run openssl or curl from your own machine.

Is the SNI checker free, and is there a limit?

It is free, with no signup or account. To keep it fast for everyone, the number of checks that can run in a short time is limited. If you reach the limit, the result says how long to wait before trying again.

Can I check a port other than 443?

No. The checker connects to the standard HTTPS port only.

All free tools

Related reading

What Is SNI? How Server Name Indication Works and How to Test ItWhat SNI is, why servers need it, what happens when the name is missing, and how to test it.