SSL/TLS Certificate Lookup

Check a domain's SSL/TLS certificate — who issued it, when it expires, and whether the chain is trusted

ec2-13-158-228-91.ap-northeast-1.compute.amazonaws.com

SSL/TLS Certificate

SSL/TLS Certificate for ec2-13-158-228-91.ap-northeast-1.compute.amazonaws.com

Hostname mismatch
Issued by (CA)
Amazon
Subject
keiai-kimitsu.jp
Valid from
Feb 17, 2026
Valid until
Mar 18, 2027 (238 days remaining)
Public key
RSA 2048-bit
Serial
027B99396F65032B3B20BF2096F0118F
SHA-256 fingerprint
D6:E3:6B:46:7C:EB:DE:9B:CA:8F:E8:47:12:B9:22:13:99:AA:B0:A9:61:50:64:80:6B:D8:DA:41:CF:7D:C4:15
Chain
Amazon RSA 2048 M04 → Amazon Root CA 1 → Starfield Services Root Certificate Authority - G2
Subject Alternative Names (36)
*.bluestellahomes.com, *.earthhome-realty.jp, *.era-awajyu.com, *.era-chuoufudousanhanbai.com, *.era-koyo-h.com, *.era-plus3.com, *.era-reformdepot.com, *.era-yoneyama.com, *.keiai-inzai.com, *.keiai-kimitsu.jp, *.keiaifckumamotokita.com, *.ki-kyotoyamashiro.jp, *.ozaco-f.jp, *.smartbace.com, *.supportgarden.com, *.takinokami-estate.com, *.tsukasa-home.com, *.zyucenter.com, bluestellahomes.com, earthhome-realty.jp, era-awajyu.com, era-chuoufudousanhanbai.com, era-koyo-h.com, era-plus3.com, era-reformdepot.com, era-yoneyama.com, keiai-inzai.com, keiai-kimitsu.jp, keiaifckumamotokita.com, ki-kyotoyamashiro.jp, ozaco-f.jp, smartbace.com, supportgarden.com, takinokami-estate.com, tsukasa-home.com, zyucenter.com

Certificate Authority Authorization (CAA)

No CAA policy is published for this domain — any certificate authority may issue for it.

Never get surprised by ec2-13-158-228-91.ap-northeast-1.compute.amazonaws.com's certificate expiring

This is today's certificate. Turn on monitoring and we'll watch ec2-13-158-228-91.ap-northeast-1.compute.amazonaws.com continuously, notifying you the moment anything moves across all three signals:

Uptime

We visit the site from multiple regions worldwide and email you within minutes if it goes down, with a per-region breakdown so a real outage stands out from a regional blip.

DNS changes

We watch NS, MX, CAA, DNSSEC, CNAME and A/AAAA records, and identify the host, network, and ASN behind them, so a real migration or hijack stands out from routine noise.

TLS certificate

We warn you 30, 14, 7, and 1 days before it expires, and flag it if the issuing authority changes or the certificate is unexpectedly replaced.

Monitor this certificate free

Free for your first domain: uptime, DNS, and certificate together. No credit card.