TLS and certificates
TLS version checker
Find out which protocol versions a web server will speak. The checker looks for obsolete versions that should be switched off (SSL 3.0, TLS 1.0 and TLS 1.1) and confirms whether TLS 1.3 is available alongside TLS 1.2.
What this checks
- The version a modern client negotiates on port 443: TLS 1.3 or TLS 1.2.
- Three separate probes, each a ClientHello offering a single obsolete version (SSL 3.0, then TLS 1.0, then TLS 1.1), and whether the server replies in that same version.
- TLS 1.3 support, taken from the first handshake when it settled on 1.3, otherwise from a second handshake that permits TLS 1.3 alone.
- Every name on its own row: the domain and its
www.name, or the single subdomain entered.
What the result means
The protocol version sets the rules for the whole connection: how keys are agreed, which ciphers are allowed and how the handshake itself is protected. SSL 3.0 is broken by the POODLE attack and was prohibited in 2015 (RFC 7568). TLS 1.0 and TLS 1.1 were deprecated in 2021 (RFC 8996), and current browsers no longer connect with them.
An old version left enabled rarely breaks anything for visitors, which is why it lingers. It still offers an attacker a weaker protocol to aim for, and baselines such as PCI DSS require early TLS to be turned off.
A pass on obsolete versions means all three probes were refused. A missing TLS 1.3 is reported as a hardening recommendation rather than a problem: TLS 1.2 with sound cipher suites remains acceptable, while TLS 1.3 connects in one round trip fewer and removes the legacy options behind past attacks.
How to fix common issues
SSL 3.0 is enabled
Disable SSL 3.0. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache use SSLProtocol -all +TLSv1.2 +TLSv1.3.
TLS 1.0 is enabled
Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.
TLS 1.1 is enabled
Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3.
TLS 1.3 is not supported
Enable TLS 1.3 alongside TLS 1.2. Recent versions of nginx, Apache, IIS (Windows Server 2022) and all major CDNs support it.
Cyber Essentials and ISO 27001
Under ISO/IEC 27001:2022, a minimum TLS version belongs in a service's documented configuration (Annex A 8.9, configuration management) and in the organisation's rules on cryptography (8.24). The probes are technical evidence of what one server accepts now. Choosing the minimum, applying it to every service and revisiting it as clients change remain the organisation's job. Cyber Essentials does not name protocol versions; its secure configuration theme is the closest fit.
Scope and limitations
- TLS 1.2 is reported only when it is the version a modern client gets. Whether a server that prefers TLS 1.3 also accepts 1.2 is not tested.
- Each obsolete-version probe offers a short list of suites common in that era. A server that accepts an old version only with a suite outside that list could be missed.
- SSL 2.0 is not probed.
- Mail servers, VPN gateways and other services that use TLS away from port 443 are outside this check.
Related guides
Questions
- Should I disable TLS 1.0 and TLS 1.1?
- Yes. RFC 8996 retired both, and no current browser needs them. Anything that still depends on them is usually an old system, better upgraded than accommodated.
- Do I need TLS 1.3?
- It is recommended rather than required. TLS 1.2 with modern cipher suites is still acceptable, but TLS 1.3 is quicker to connect and leaves out options that caused earlier vulnerabilities. Current web servers and CDNs support it.
- Why is TLS 1.2 shown as not tested?
- When the server negotiates TLS 1.3, this checker does not open a separate TLS 1.2-only connection, so it cannot say whether 1.2 is also accepted. Most servers keep TLS 1.2 on for clients that lack 1.3.
Related security tools
- TLS cipher checker - See whether a server accepts broken or weak cipher suites such as RC4, 3DES or export ciphers.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- HSTS checker - Check Strict-Transport-Security: max-age, includeSubDomains, preload and the HTTP redirect.
- End-of-life software checker - See whether a site advertises software versions that no longer receive security fixes.

