What the badge says, and what it does not
A badge reports one observed value and who observed it: "SSL · 63 days left · OrbitProbe", "Domain · 212 days left · OrbitProbe" or "DMARC · p=reject · OrbitProbe". It is a reading, not a certificate. It does not say that a site is safe, that a certificate is configured correctly or that anyone owns anything.
When the value cannot be read (the lookup failed, the registry publishes no expiry date, the rate limit was reached) the badge says "unknown". It never falls back to a good-looking value.
How fresh it is
The value comes from the same live engine as the tools on this site, from one server location. A badge with a value may be cached for up to one hour by browsers and proxies; an "unknown" badge for one minute. Image proxies such as the one GitHub uses for READMEs keep their own copy and can hold it longer.
Badge requests count against the same per-address rate limit as the public API. A page with many visitors is fine, because cached results do not count.
URL format
The image lives at /badge/<domain>.svg. Add ?type=ssl, ?type=expiry or ?type=dmarc to choose the value (ssl is the default) and &style=dark for dark backgrounds. The text on the badge is English in every language. The SVG contains no scripts, fonts or external references, so it renders inside an <img> tag under a strict content security policy.