SSL
GET
https://api.deepinfo.com/v1/lookup/sslConnects to a host in real time and returns the SSL/TLS certificate it serves: subject, issuer, validity, fingerprints, extensions (including all DNS names in the Subject Alternative Name) and whether the signature and chain are valid.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
target | Required | Domain name or IP address to connect to. Example deepinfo.com |
port | Optional | Port to connect to. Default 443.Example 443 |
proxy | Optional | Optional proxy to connect through, in the form scheme://user:password@host:port. |
Response Fields
| Field | Description |
|---|---|
target | The host that was checked |
port | The port that was checked |
connection_ | success, timeout, refused, reset, ssl_error, not_resolved or proxy_ |
parsed | Parsed certificate, with the parsed.* fields below. null if no certificate was retrieved |
parsed. | Certificate version, e.g. v3 |
parsed. | The version number as encoded in the certificate ( 2 for v3) |
parsed. | Subject distinguished name |
parsed. | Subject common name (CN) |
parsed. | Subject organization (O) |
parsed. | Subject organizational unit (OU) |
parsed. | Subject locality (L) |
parsed. | Subject state or province (ST) |
parsed. | Subject country (C) |
parsed. | Issuer distinguished name |
parsed. | Issuer common name (CN) |
parsed. | Issuer organization (O) |
parsed. | Issuer organizational unit (OU) |
parsed. | Issuer locality (L) |
parsed. | Issuer state or province (ST) |
parsed. | Issuer country (C) |
parsed. | Start of the validity period |
parsed. | End of the validity period |
parsed. | Length of the validity period, in seconds |
parsed. | Whether the signature is valid |
parsed. | Whether the certificate chain is valid |
parsed. | Whether the certificate is self-signed |
parsed. | Why the signature or the chain is not valid; null when both are valid |
parsed. | The signature, base64-encoded |
parsed. | OID of the signature algorithm |
parsed. | Name of the signature algorithm, e.g. sha256 |
parsed. | SHA-1 fingerprint of the certificate |
parsed. | SHA-256 fingerprint of the certificate |
parsed. | MD5 fingerprint of the certificate |
parsed. | Fingerprint of the signed part of the certificate (TBS certificate) |
parsed. | Serial number |
parsed. | The certificate's public key: its algorithm, fingerprint and key parameters |
parsed. | X.509 extensions. parsed. holds every DNS name in the Subject Alternative Name |
parsed. | Whether the certificate has expired |
parsed. | Host names the certificate is valid for |
certificate | The certificate in base64 (DER) |
parse_ | Problems found while parsing the certificate |
check_ | When the check was performed (UTC) |
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
target | string | "deepinfo.com" |
port | number | 443 |
check_date | string | "2026-09-22T12:26:02Z" |
connection_status | string | "success" |
parsed | object | |
parsed. | object | |
parsed. | string | "v3" |
parsed. | string | "2" |
parsed. | string | "5102c880b9f106836e519b298180d61b676…" |
parsed. | string | "12a3374625c71344dca023d3fd679c8603b…" |
parsed. | string | "d168f284acc2bd12ef0942ca7b8437ce" |
parsed. | object | |
parsed. | string | "CN=deepinfo.com" |
parsed. | string | "deepinfo.com" |
parsed. | null | |
parsed. | null | |
parsed. | null | |
parsed. | null | |
parsed. | null | |
parsed. | object | |
parsed. | string | "MEQCIBNf/tDQrmobCrlLn6qx00hK9xB2VIs…" |
parsed. | boolean | false |
parsed. | boolean | true |
parsed. | boolean | true |
parsed. | null | |
parsed. | object | |
parsed. | string | "1.2.840.10045.4.3.2" |
parsed. | string | "sha256" |
parsed. | object | |
parsed. | string | "2026-08-22T16:13:55Z" |
parsed. | number | 7779585 |
parsed. | string | "2026-11-20T17:13:40Z" |
parsed. | object | |
parsed. | string | "CN=WE1,O=Google Trust Services,C=US" |
parsed. | string | "WE1" |
parsed. | string | "US" |
parsed. | null | |
parsed. | string | "Google Trust Services" |
parsed. | null | |
parsed. | null | |
parsed. | object | |
parsed. | object | |
parsed. | boolean | true |
parsed. | boolean | false |
parsed. | boolean | false |
parsed. | boolean | false |
parsed. | boolean | false |
parsed. | boolean | false |
parsed. | boolean | false |
parsed. | object | |
parsed. | boolean | true |
parsed. | object | |
parsed. | boolean | false |
parsed. | object | |
parsed. | string | "p0cCg0usJcT4dOaSGZXGwJBtEBw=" |
parsed. | object | |
parsed. | string | "kHeSNWfE/6jMqeZ72YB5e8yT+Tg=" |
parsed. | object | |
parsed. | string | "http://i.pki.goog/we1.crt" |
parsed. | object | |
parsed. | array< | "deepinfo.com" |
parsed. | array< | "2.23.140.1.2.1" |
parsed. | array< | "http://c.pki.goog/we1/hxWfeVec_R4.c…" |
parsed. | array< | |
parsed. | string | "wjF+V0UZo0XufzjespBB68fCIVoiv3/Vta1…" |
parsed. | number | 1787418836 |
parsed. | number | 0 |
parsed. | string | "MEQCICgG2IGcayVZ+Ttkz2l/ZwOu8iCGIvP…" |
parsed. | array | |
parsed. | string | "17509925249078317932559944742653578…" |
parsed. | string | "8fd171df12e6296f987fbb69506eb38cfbf…" |
parsed. | object | |
parsed. | object | |
parsed. | string | "sha256" |
parsed. | string | "12a3374625c71344dca023d3fd679c8603b…" |
parsed. | object | |
parsed. | string | "ECDSA" |
parsed. | object | |
parsed. | string | "256" |
parsed. | string | "21201999730139012709824012335874547…" |
parsed. | string | "45576670326640749315426684723968379…" |
parsed. | boolean | false |
parsed. | array< | "deepinfo.com" |
certificate | string | "MIIDfTCCAySgAwIBAgIRAIO6460sp0mAE8q…" |
parse_errors | array |
Errors
400 if target is missing or invalid. Connection problems are not errors: they return 200 with the reason in connection_status.
Examples
The saved example from the Deepinfo API, shown in the request and response panels.
- deepinfo.com:443
GET/lookup/ssl?target=deepinfo.com200 OK
Worked Examples
Worked examples of this endpoint, each on its own page with the exact request and the response it returns.
- Certificate of a DomainThe certificate of deepinfo.com: issued by Google Trust Services (WE1) for deepinfo.com and *.deepinfo.com, valid, ECDSA key.
- Mail Server on Port 465The certificate of smtp.gmail.com on port 465 (SMTP over TLS): issued by Google Trust Services WR2.
- An Expired CertificateAn expired certificate: has_expired is true and invalid_reason says "certificate has expired" (it ended in April 2015).
- A Certificate for Another Host NameA certificate for another host name: valid is false with "Hostname mismatch" for wrong.host.badssl.com.