The incomplete chain, and why it only breaks for some people
A server must send its own certificate plus the intermediates that connect it to a trusted root. When it sends only its own, some clients still work - because they happen to have cached the intermediate from another site - and others fail completely. The result is a site that works in your browser, works for most of the office, and is untrusted on a colleague phone or on a server making an API call.
This is the most common TLS misconfiguration and the hardest to diagnose from the inside, precisely because the person checking is usually one of the people for whom it works. A checker fetching the chain from outside sees what is actually being sent rather than what your browser has assembled from its own cache.
Expiry is a calendar problem disguised as a technical one
Certificates expire, automated renewal fails silently, and the failure surfaces as a total outage with a frightening browser warning rather than as a degraded service. Nothing about it is subtle: at the expiry moment the site simply stops being usable for everyone at once, and the people best placed to notice early are asleep.
The defence is knowing the date before it arrives and monitoring the renewal rather than trusting it. Checking by hand answers today question; if the answer matters more than once, an uptime monitor that watches the certificate is the thing that actually prevents the outage.
What the certificate covers is a separate question from whether it is valid
A perfectly valid certificate produces a browser warning if the name does not match. Wildcards are the usual cause of confusion: a wildcard covers one level of subdomain and no more, so it secures the direct children of a domain and not their children in turn. A certificate for the bare domain does not automatically cover the www version, and vice versa, unless both are listed.
So when a site is trusted on one hostname and warns on another, the certificate is usually fine and the list of names on it is the problem. Reading that list settles it immediately, and it is the second question after expiry rather than a separate investigation.