TLS / Certificate Checker
Check a site's TLS version, certificate issuer and expiry.
About this check
TLS encrypts traffic between browsers and your server. Modern sites should negotiate TLS 1.2 or 1.3; older protocols (TLS 1.0/1.1, SSLv3) are deprecated and insecure. Certificates must be valid and not close to expiry.
This tool performs a verified TLS handshake on port 443 and reports the negotiated protocol, the certificate issuer and how many days remain before it expires.
Frequently asked questions
What TLS version is safe?
TLS 1.2 and 1.3. Disable TLS 1.0/1.1 and SSLv3.
How early should I renew certificates?
Automate renewal well before expiry — under ~14 days remaining is a warning sign.
Want the full picture?
Get a complete security report with an exposure score across email, DNS, TLS, exposure and breach metadata.
Run a full report All tools