SSL/TLS Certificate Lookup
Check a domain's SSL/TLS certificate — who issued it, when it expires, and whether the chain is trusted
SSL/TLS Certificate for kfw.com
Hostname mismatch- Issued by (CA)
- Deutsche Telekom Security GmbH
- Subject
- *.kfw.de
- Valid from
- Sep 2, 2026
- Valid until
- Mar 18, 2027 (173 days remaining)
- Public key
- RSA 4096-bit
- Serial
- 24E5E326C0C95BAEE37B30BC0A2E0FAE
- SHA-256 fingerprint
- F9:9C:9C:78:1F:56:3A:76:53:47:A9:1A:EA:88:7E:FF:87:29:72:76:58:1F:4F:90:21:F2:09:60:E4:C4:F8:E5
- Chain
- Telekom Security OV RSA CA 26A → Telekom Security TLS RSA Root 2023
Certificate Authority Authorization (CAA)
CAA restricts issuance to telesec.de; we couldn't map the serving CA (Deutsche Telekom Security GmbH) to one of these identifiers.
Never get surprised by kfw.com's certificate expiring
This is today's certificate. Turn on monitoring and we'll watch kfw.com continuously, notifying you the moment anything moves across all three signals:
Uptime
We visit the site from multiple regions worldwide and email you within minutes if it goes down, with a per-region breakdown so a real outage stands out from a regional blip.
DNS changes
We watch NS, MX, CAA, DNSSEC, CNAME and A/AAAA records, and identify the host, network, and ASN behind them, so a real migration or hijack stands out from routine noise.
TLS certificate
We warn you 30, 14, 7, and 1 days before it expires, and flag it if the issuing authority changes or the certificate is unexpectedly replaced.
Free for your first domain: uptime, DNS, and certificate together. No credit card.