Name and mail

How to read the certificate issuer

You expect Let's Encrypt, a company CA, or Cloudflare, and need to see who actually signed. Read the issuer on SSL Expiry Checker.

The issuer is the signing certificate, not the site brand.
The issuer is the signing certificate, not the site brand, and expiry still belongs to this leaf.

What to run

Open SSL Expiry Checker. The result is from Cloudflare. It reads the peer certificate. It does not grade the whole TLS config.

How to read the result

Issuer is the signing certificate's subject, not the site brand.

A different issuer after a proxy change is normal.

Expiry still belongs to this leaf.

What to open next

Open HTTP Headers for strict-transport-security if the question is whether you are forcing HTTPS, not who signed. That result is from Cloudflare.

Related tools