Free diagnostic toolReviewed 2026-08-07By HostWithShery technical editorial

Mixed-Content Checker

Load the public HTTPS page and identify insecure HTTP resources referenced by the returned HTML.

Live tool

Mixed-Content Checker

Run the public check first. The explanation below tells you how to interpret and repair the result.

No accountPublic evidence only
Live public check

Scans the returned HTML for src/href references that still use plain HTTP.

No account · Public configuration only
Readable result firstRaw data stays availableRelated repair paths included
On this page

Mixed-Content Checker: the question this tool answers

Mixed-Content Checker answers one focused troubleshooting question: mixed content checker. The live result is designed to tell you whether HTTPS page retrieval is usable, whether http:// resource references agrees with it, and whether resource type hints exposes a second path that can explain the symptom. A healthy result here is not an all-purpose website score; it only describes the TLS, certificate and HTTPS evidence this tool owns.

  • HTTPS page retrieval
  • http:// resource references
  • resource type hints
  • certificate status context

How to read the HTTPS page retrieval, http:// resource references and resource type hints evidence

Start with the value that directly controls the failing service, then use the other signals to confirm or challenge that interpretation. A single record or response can look correct while another hostname, IP family, redirect or mail-authentication path still fails. The tool therefore keeps the raw observed value visible and explains how the signals relate.

  • HTTPS page retrievalRecord the public status, final URL and relevant response headers. A working DNS answer does not prove that the application is serving a genuine website response.
  • Http:// resource referencesRecord the public status, final URL and relevant response headers. A working DNS answer does not prove that the application is serving a genuine website response.
  • Resource type hintsVerify resource type hints from the public Internet and compare it with the value the responsible provider says should be live.
  • Certificate status contextTest the hostname actually requested, its certificate dates and SAN coverage, and the TLS handshake. Root and www can serve different certificates.

Common mixed-content checker failure patterns

The most useful warnings are mismatches rather than isolated missing fields. HTTPS page retrieval can be absent or stale; http:// resource references can point somewhere different from the expected provider; and resource type hints can reveal a second path that behaves differently. If public sources disagree, first decide whether the difference comes from authoritative data, caching, a separate hostname, IPv6, or another protocol layer before editing configuration.

What to change — and what not to change

Change the smallest setting that the evidence proves is wrong. Compare the observed HTTPS page retrieval with the current value supplied by the responsible provider, save the existing value, make one correction, and retest. Do not replace nameservers, delete unrelated MX/TXT records, disable TLS controls or remove IPv6 simply because Mixed-Content Checker shows a warning in another layer. Broad changes can turn one isolated problem into several independent outages.

How HostWithShery runs Mixed-Content Checker

The submitted public input is normalized and validated before any server-side request is made. HostWithShery then obtains HTTPS page retrieval and http:// resource references using the appropriate public DNS, HTTP, TLS or mail protocol and adds resource type hints plus certificate status context where it materially changes the interpretation. URL-based checks are restricted to public destinations, and redirect targets are revalidated instead of being trusted automatically.

Example mixed-content checker interpretation

Example only: suppose HTTPS page retrieval returns an expected value, but http:// resource references points to an older destination while resource type hints shows a different result for another hostname or network path. The correct conclusion is not “everything is broken.” It is that one public path still disagrees with the intended TLS, certificate and HTTPS configuration. The live result uses the domain you enter; this example is never presented as evidence about your site.

When a mixed-content checker result is inconclusive

This is a public-configuration diagnostic. Network filtering, private control-panel settings, split-horizon DNS, provider-internal state and transient routing conditions can limit what can be confirmed from outside the account. Public diagnostics cannot see private control-panel state, unpublished origin addresses, provider account status or split-horizon/internal DNS. If the remote service times out, blocks automated requests or hides a signal, the result stays inconclusive instead of inventing a provider or configuration. That distinction matters when the next step is a potentially disruptive DNS, SSL or mail change.

How to verify the repair

HTTPS should complete for the exact hostname, the certificate should be valid for that hostname, and root/www should follow the intended canonical redirect without a TLS error. Repeat Mixed-Content Checker after the change and compare the same HTTPS page retrieval, http:// resource references and resource type hints evidence that exposed the problem. A provider dashboard saying “saved” is not enough when the public Internet still returns the old value.

What to check next if Mixed-Content Checker is healthy

If HTTPS page retrieval, http:// resource references and resource type hints now agree but the user-facing problem remains, move to the adjacent layer instead of editing the same setting repeatedly. Use the related diagnostics on this page to test the next plausible cause, and keep the previous result as evidence when escalating to a hosting, DNS or email provider.

Technical references

These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.