TLS and certificates
SSL/TLS checker
Test a website's HTTPS set-up in one run: whether it answers over TLS, whether its certificate is trusted and in date, which protocol versions it still accepts and whether it agrees to a weak cipher. Secure connections today use TLS; SSL is its broken predecessor, though the old name stuck.
What this checks
- A TLS 1.2 or 1.3 handshake on port 443 with the domain and its
www.name (or only the name you enter, for a subdomain), recording the version, cipher suite and ALPN protocol agreed. - The certificate served for each name: trust, hostname coverage, validity dates and the days left before it expires.
- Whether the server answers a client that offers only SSL 3.0, only TLS 1.0 or only TLS 1.1.
- Whether TLS 1.3 is available, using a second handshake that allows nothing older when the first one settled on TLS 1.2.
- Whether the server picks a suite from a list made up entirely of broken ones: RC4, DES, 3DES, NULL, export-grade and anonymous.
What the result means
SSL (Secure Sockets Layer) was the first protocol for encrypted web traffic. TLS (Transport Layer Security) replaced it in 1999, and SSL 2.0 and SSL 3.0 have both since been prohibited (RFC 6176, RFC 7568). A browser showing a secure connection today is using TLS 1.2 or TLS 1.3. "SSL" survives in product names and in "SSL certificate", which means the certificate a TLS server presents.
Results are listed per host, because the bare domain and its www. name can be served by different machines with different certificates. A pass means that one check found nothing to report. It does not show that the site, or the server behind it, is secure.
Certificate findings tend to be the urgent ones: an expired, untrusted or wrongly named certificate puts a full-page browser warning in front of every visitor. Obsolete versions and weak suites are less visible but hand an attacker on the network path known weaknesses to work with. A missing TLS 1.3 is a recommendation, since TLS 1.2 on its own remains acceptable.
How to fix common issues
Website is not available over HTTPS
Install a certificate and serve the site over HTTPS. Free certificates are available from Let's Encrypt, and most hosts and CDNs can provision them automatically.
Certificate has expired
Renew the certificate and install it. Automate renewal (for example with ACME/Let's Encrypt or your host's managed certificates) so it does not happen again.
Certificate is not trusted
Install a certificate from a public certificate authority, and configure the server to send the full chain (your certificate plus intermediates).
Certificate does not cover this hostname
Issue a certificate whose subject alternative names include this hostname, or a wildcard that covers it, and install it.
TLS 1.0 is enabled
Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.
Weak cipher suites accepted
Restrict the server to modern AEAD cipher suites (AES-GCM, ChaCha20-Poly1305). Mozilla's SSL Configuration Generator produces a correct configuration for most servers.
Cyber Essentials and ISO 27001
Cyber Essentials does not specify TLS versions or certificates. Its secure configuration theme does cover the internet-facing services in scope, and a run like this one is technical evidence of how one of those services is set up as the internet sees it.
In ISO/IEC 27001:2022 the nearest Annex A controls are 8.24 (use of cryptography) and 8.21 (security of network services). The organisation still has to decide its own TLS baseline, name an owner for each public service and review the settings when they change. The check shows the result at one moment, not that any of that is in place.
Scope and limitations
- Only port 443 is tested, at one address per host (IPv4 first). Other addresses behind the same name, and TLS on other ports such as mail or admin services, are not checked.
- Where a CDN or reverse proxy terminates TLS, the results describe that edge, not the origin server behind it.
- The cipher test offers a fixed list of broken suites rather than listing everything the server supports, and TLS 1.2 is not tested on its own.
- HTTP behaviour on top of TLS, such as the redirect from plain HTTP and the
Strict-Transport-Securityheader, belongs to the HSTS and security headers checkers.
Related guides
Questions
- Is SSL the same as TLS?
- Not quite. TLS is the protocol that succeeded SSL, and every SSL version is now prohibited. People still say SSL out of habit, so an SSL checker in practice tests TLS.
- Does an SSL checker test my server or my CDN?
- Whatever answers on port 443 for the name. If a CDN or proxy handles TLS for the site, the results describe its configuration; the connection from it to your origin server cannot be seen from outside.
- Is a site with a valid certificate safe?
- A valid certificate shows that the connection is encrypted to a server holding a certificate for that name. It says nothing about the site itself, its software or how it handles data.
Related security tools
- HSTS checker - Check Strict-Transport-Security: max-age, includeSubDomains, preload and the HTTP redirect.
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.
- CAA checker - See which certificate authorities a domain allows to issue its certificates.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

