Security Tools

TLS Configuration Checker

Check a server’s TLS setup in one go. Our server makes a real handshake for each protocol version – TLS 1.0, 1.1, 1.2 and 1.3 – reads the certificate (trust, host match, expiry, key and signature), checks whether http:// redirects to https:// and whether HSTS is sent. Deprecated versions that are still enabled are flagged, and a version our own OpenSSL cannot offer is reported as “not tested” instead of being guessed.

  • Encrypted connection
  • No sign-up
  • Free to use

Our server makes a few TLS handshakes to port 443 (one per protocol version), reads the certificate and checks HTTPS redirects and HSTS. Handshakes use OpenSSL on our server; a version it cannot offer is reported as “not tested”, never guessed.

How to use TLS Configuration Checker

  1. Enter a domain.
  2. Click Check TLS.
  3. Disable TLS 1.0/1.1 if enabled.
  4. Add HSTS and a 301 redirect if missing.

TLS Configuration Checker features

Real handshakes

One per protocol version.

Certificate

Trust, match, expiry, key.

Redirect and HSTS

The full HTTPS picture.

Grade

Rule-based score.

Honest results

“Not tested” when unknown.

Fast

Handshakes run in parallel.

When to use TLS Configuration Checker

  • Compliance checks (PCI DSS).
  • Server hardening.
  • Hosting and CDN migrations.
  • Monitoring after certificate renewals.

TLS Configuration Checker FAQ

Why disable TLS 1.0 and 1.1?

They are deprecated by RFC 8996, have known weaknesses and are not allowed by PCI DSS.

Do I need TLS 1.3?

It is faster and more secure; all modern browsers support it. Keep TLS 1.2 for older clients.

What does “not tested” mean?

Our server’s TLS library cannot offer that version, so the result is unknown rather than guessed.

What is HSTS?

A header that tells browsers to use HTTPS only for your site.

Modern TLS in practice

A good baseline is Mozilla’s “intermediate” configuration: TLS 1.2 and 1.3, ECDHE key exchange with AES-GCM or ChaCha20, automatic certificate renewal and HSTS.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.

Other useful tools