Skip to content

SSL / TLS Checker

Inspect a site's TLS certificate, expiry, issuer and negotiated protocol, with a renewal calendar you can download and a full report.

Runs on the XGM server. Nothing is stored.

A hostname served over HTTPS; add :port for another port. Press Enter to run. Try , , .

About this tool

TLS Checker connects to the host from the XGM server and reports what the handshakes reveal: the certificate as a browser validates it (trusted chain, matching name, dates, days remaining, Subject Alternative Names), the key type, size and signature algorithm read from the certificate itself, one handshake per protocol version from TLS 1.0 to TLS 1.3, handshakes that offer only weak cipher groups, OCSP stapling, the Strict-Transport-Security header and the preload status of the domain. The grade starts at A and is lowered by caps: the worst cap wins, and HSTS with a max-age of at least 15,552,000 seconds (180 days) lifts an A to A+. Add :port to test TLS on a port other than 443. It does not fetch or judge the page content, does not simulate individual browsers or their own root stores, and does not test for named TLS vulnerabilities such as Heartbleed or ROBOT.

XGM connects from its server: one verified handshake for the certificate, one handshake per protocol version (TLS 1.0 to 1.3), handshakes that offer only weak cipher groups, a TLS 1.2 handshake that asks for a stapled OCSP response, and an HTTPS request for the HSTS header. The HSTS preload status comes from hstspreload.org. The grade follows SSL Labs-style caps: untrusted or expired certificate F, 3DES or RC4 C, TLS 1.0/1.1 B, no TLS 1.3 A-, HSTS of six months or more on an A lifts it to A+. The renewal calendar under the certificate finding is built in your browser from the dates in this result; the .ics file is assembled on the page and downloaded locally, not fetched from a server.

How to use it

  1. Open the TLS Checker tool.
  2. Enter the public domain, hostname or IP address you want to check.
  3. Run the check; XGM queries it from its server and lists the findings.
  4. Copy the output only after checking it looks correct.
  5. Use related XGM tools if you need a broader diagnostic view.

FAQ

What lowered my grade?

The grade begins at A and each problem applies a cap; the worst one wins and every applied cap is listed next to the grade. An untrusted or expired certificate, a SHA-1 or MD5 signature, an RSA key under 1024 bits, or no TLS 1.2 and no TLS 1.3 cap the result at F; accepted RC4 or 3DES caps it at C; TLS 1.0 or 1.1 still enabled caps it at B; a server without TLS 1.3 caps it at A-. Only an A rises to A+, and only when the Strict-Transport-Security header carries a max-age of 15,552,000 seconds or more.

Can I get a reminder before the certificate expires?

The certificate finding carries a renewal calendar: the expiry itself, the 30-day mark where certbot and other ACME clients start renewing, the 60-day mark a hand-installed one-year certificate needs, and the date a 90-day certificate would have been issued. If the scan found an intermediate that expires before the leaf, or a second certificate with a different key algorithm, those dates are in it too. Download it as an .ics file and import it into any calendar; the file is built in your browser from the result on screen, and XGM stores nothing and sends you nothing.

Why is this grade different from an SSL Labs run?

SSL Labs builds a weighted score from certificate, key exchange and cipher strength and then applies its caps; XGM applies only the caps listed above to a starting A, so the two agree on obvious failures and can differ in the middle. XGM also does not run browser and client simulations, does not enumerate every cipher suite the server accepts, and does not test named vulnerabilities such as Heartbleed, ROBOT or insecure renegotiation. Treat the grade here as a fast check of certificate, protocol versions, weak cipher groups and HSTS, not as a replacement for a full audit.

My browser accepts the certificate, so why does XGM say it is not trusted?

The usual cause is a missing intermediate: the server sends only its own certificate, and the verification here fails with “unable to get local issuer certificate”. Browsers often repair that by fetching the intermediate from the AIA extension, while API clients, mail servers and command-line tools simply fail. Serve the full chain (fullchain.pem in nginx, not cert.pem) and the finding disappears.

Why does OCSP stapling say “not checked”?

Stapling is probed with a hand-built TLS 1.2 ClientHello carrying the status_request extension, and the answer is read from the CertificateStatus message. A server that refuses TLS 1.2, or only offers TLS 1.3 - where that message is sent inside the encrypted handshake - gives no readable answer, so the result is unknown rather than yes or no. Since Let's Encrypt stopped issuing OCSP responses in 2025, “no stapling” on such a certificate is also expected rather than a misconfiguration.

A weak cipher group was accepted but the grade is still A. Why?

Only RC4 and 3DES cap the grade, at C. The other two groups tested here - RSA key exchange without forward secrecy, and CBC suites with SHA-1 - are reported as findings but do not lower the grade, because they are weaknesses rather than broken primitives. Fix them anyway: without forward secrecy a stolen private key decrypts previously recorded traffic, and AEAD suites (GCM, ChaCha20-Poly1305) avoid the padding-attack history of CBC.

Read the full SSL / TLS Checker guide

Further reading