security / ssl / tls / domain coverage
SSL / TLS

Domain coverage

A certificate must actually cover the exact domain name visitors use, including the www version, or the browser rejects it.

Severity if missing
High
Category
SSL / TLS
Standard
RFC 5280

What it is

A certificate lists the exact domain names it's valid for. If a visitor reaches your site at a name that isn't on that list — for example www.yourdomain.com when the certificate only covers yourdomain.com — the browser sees a mismatch and refuses to trust it.

Good coverage means the certificate includes every name your site is served under.

Why it matters

A certificate that doesn't cover the name in the address bar triggers the same alarming warning as no certificate at all. It's a common oversight, especially with the www and non-www versions of a domain, and it blocks visitors just as effectively as an expired certificate.

The risk
If the certificate doesn't cover the exact domain a visitor uses, the browser shows a name-mismatch warning and blocks the connection.

How Pentrawl checks it

Pentrawl checks the names listed on your certificate and confirms that they cover the domain being scanned. Correct coverage passes the check.

How to fix it

Issue a certificate that includes every name your site uses. Most providers let you add both the bare domain and the www version, or cover everything with a wildcard.

Recommended
Include both yourdomain.com and www.yourdomain.com on the certificate.
Check your domain's Domain coverage in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →