Skip to content

HTTPS configuration checker

Catch deprecated protocol versions, missing HSTS and broken HTTP redirects before a compliance scan or a customer does.

Anonymous checks are limited to 10 per minute and 60 per hour per address. Results are cached for 60 seconds and not published anywhere.

How it measures

  • One unvalidated handshake per protocol version (TLS 1.0, 1.1, 1.2, 1.3) records what the server accepts; these diagnostic handshakes never influence any monitor.
  • A separate validated handshake decides whether the certificate is trusted by a public root store.
  • A GET to the HTTPS URL reads Strict-Transport-Security; a GET to the same path on port 80 records whether it redirects to HTTPS.
  • HTTP/2 support is read from ALPN negotiation, not from a full HTTP/2 request.

Limits

  • Cipher suite strength, OCSP stapling, certificate transparency and key sizes are not graded.
  • Checks run against the first resolved address only; load-balanced pools can differ per node.
  • The HTTP redirect test only runs for the standard port 443.
  • When the certificate is untrusted the HTTPS request is refused by design, so HSTS is reported as unreadable rather than guessed.

Troubleshooting

TLS 1.0 or 1.1 accepted
Disable them in the web server or load balancer configuration (for example ssl_protocols TLSv1.2 TLSv1.3 in nginx). Both are deprecated by RFC 8996.
HSTS missing
Add Strict-Transport-Security: max-age=31536000; includeSubDomains once every subdomain serves HTTPS. Start with a short max-age if unsure.
Plain HTTP serves content
Return a 301 to the HTTPS URL for every request on port 80; otherwise users who type the hostname stay on HTTP.

Related tools