We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Check which SSL/TLS protocol versions a public server accepts. Find legacy TLS 1.0 or 1.1 exposure and verify TLS 1.2 and 1.3 handshakes.
Supports domain names, URLs with protocols, or host:port format. Default port is 443.
Active TLS checks send multiple probes. Scan only systems you own or are authorized to assess.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
An HTTPS page loading in your browser proves only that one client and one server endpoint completed an encrypted connection. It does not show which older protocols remain enabled.
RFC 8996 formally deprecated TLS 1.0 and 1.1 in 2021. A common modern baseline is TLS 1.2 for compatibility with TLS 1.3 enabled where supported.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Provide a domain, IP address, or host:port such as example.com:443.
This mode checks protocol negotiation and skips the broader vulnerability suite.
Review the responses for TLS 1.0, 1.1, 1.2, and 1.3.
After changing a web server, proxy, or cloud TLS policy, scan the public endpoint again.
Use cases
See how the tool fits into real work and everyday tasks.
After setting a minimum TLS version, verify that the public listener no longer accepts TLS 1.0 or 1.1 while required TLS 1.2 and 1.3 handshakes still work.
Check the CDN hostname, any public origin hostname, and regional endpoints separately to find protocol-policy drift between edge and origin services.
Share the observed version list with client owners when planning to retire old devices. A browser’s local capabilities do not represent every customer’s operating system or application.
Q&A
Find concise answers to common questions and confusing cases.
No.
Not automatically.
The browser may use another DNS address, proxy, or network path.
Some old operating systems, devices, and applications depend on TLS 1.0 or 1.1.
Notes
Review scope, result limitations, and important precautions before use.
Protocol probing opens network connections and sends TLS handshakes.
RFC 8996 deprecates TLS 1.0 and TLS 1.1, but a migration plan still needs to account for application compatibility.
An “undetermined” state or failed scan does not prove that a protocol is disabled.
Related
Discover related tools, collections, and available API capabilities.