TLS Protocol Version Diagnostic Tool
Enter a domain name to check which TLS versions (1.0-1.3) it supports. Instantly see whether deprecated legacy versions are still enabled on your server, for free.
What is TLS version diagnosis
TLS (Transport Layer Security) is the protocol that encrypts communication between a website and a browser, and four versions currently exist: 1.0, 1.1, 1.2, and 1.3. TLS 1.0 and 1.1 were formally deprecated in 2021 due to known weaknesses exploited by attacks such as BEAST and POODLE, yet they remain enabled on a server unless an administrator explicitly disables them. This tool lets you enter a domain name and see, from the outside, which versions the server actually accepts.
The diagnosis works by attempting a handshake on port 443 (HTTPS) of the target domain while explicitly specifying each TLS version in turn, from 1.0 through 1.3, and recording whether the connection succeeds. Rather than inspecting the contents of a certificate, it targets the server-side configuration itself — namely, which protocol versions it is willing to speak. That makes it well suited to self-checking the "disable deprecated protocols" requirement demanded by external audits such as PCI DSS (the payment card industry security standard).
How to use the TLS version diagnostic tool
- Enter a domain name Type the domain name of the site you want to check, such as `example.com`. There is no need to include `https://` or a path.
- Click "Check" The tool attempts a handshake on port 443 of the target domain, once for each of the four TLS versions from 1.0 to 1.3.
- Review the per-version results The table shows "Connectable" or "Not connectable (disabled)" for each version, so you can see at a glance which ones are enabled.
- Check the overall verdict A single verdict of "Good," "Caution," or "Danger" tells you immediately whether the configuration needs attention.
- Fix the server configuration if needed If a deprecated version is still enabled, plan to disable it; if a modern version is unsupported, suspect a misconfiguration and contact your server administrator or hosting provider.
Tips for getting more out of it
- PCI DSS (the payment card industry security standard) has required disabling TLS 1.0/1.1 as "insufficiently secure protocols" since 2018. Sites handling payments should check this first.
- Unlike an SSL certificate checker, which inspects the expiry date and issuer of a certificate, this tool diagnoses the protocol-level configuration itself — which versions the server is willing to negotiate. Using both together gives a fuller picture.
- Leaving TLS 1.0/1.1 enabled won't break ordinary traffic immediately, but major browsers are increasingly moving toward rejecting them by default, so disabling them early reduces future compatibility risk.
- Conversely, if both TLS 1.2 and 1.3 are disabled, that strongly suggests a misconfiguration, since modern browsers may be unable to connect at all — treat this as the highest-priority issue to fix.
- If your site runs on shared hosting or behind a CDN, TLS version settings are usually controlled by the hosting provider, so report any issues found here to their support team.
When to use TLS version diagnosis
Confirming configuration after a server migration
Switching hosting providers or updating the OS can silently reset TLS settings to their defaults. Running this check as a final step of the migration catches that early.
Preparing for a security audit or vulnerability assessment
Checking in advance that legacy protocols are already disabled reduces the number of findings an external auditor will raise.
Self-checking PCI DSS compliance
Sites that process payments are required by PCI DSS to disable TLS 1.0/1.1. This tool is well suited to periodic self-checks between formal audits.
Verifying an e-commerce or membership site
Sites handling personal data or card information have the most to lose from a neglected legacy protocol, so building a habit of regular checks pays off.
Auditing settings across multiple domains
If you run several subdomains or related sites, checking each one individually with this tool reveals inconsistencies in configuration between them.
TLS version diagnosis glossary
- TLS
- Short for Transport Layer Security, the protocol that encrypts traffic between a website and a browser. The current versions in active use are 1.2 and 1.3, and the padlock icon in a browser's address bar indicates that TLS encryption is in effect.
- SSL
- The predecessor to TLS. Both SSL 2.0 and 3.0 had fundamental design flaws and have since been replaced by TLS, though the name "SSL" is still commonly used out of habit, as in "SSL certificate."
- Handshake
- The negotiation a client and server perform before starting encrypted communication, during which they agree on the TLS version and cipher suite to use. This tool checks whether that negotiation succeeds for each version.
- Cipher suite
- A combination of algorithms used for key exchange, encryption, and tamper detection. The set of available cipher suites differs by TLS version, and TLS 1.3 removes older, vulnerability-prone options from its specification entirely.
- PCI DSS
- A security standard for organizations that handle credit card data. Since 2018 it has required disabling TLS 1.0/1.1 as "insufficiently secure protocols."
- Downgrade attack
- An attack technique that tricks a connection into using an older, weaker protocol version mid-negotiation. Leaving a deprecated version enabled gives this kind of attack a foothold.
- Deprecated
- A status indicating a standard is no longer formally recommended for use. TLS 1.0/1.1 were formally deprecated by the IETF in 2021, but they continue to function unless a server administrator explicitly disables them.
Frequently asked questions
Side Note — The evolution of TLS versions and their vulnerabilities
SSL, the predecessor of TLS, was developed by Netscape in the mid-1990s, but both SSL 2.0 and 3.0 had fundamental design flaws. TLS 1.0, standardized in 1999 as SSL 3.0's successor, still suffered from improper handling of initialization vectors in CBC-mode ciphers in some implementations — a weakness demonstrated by the BEAST attack in 2011.
In 2014, the POODLE attack exposed a design flaw in SSL 3.0 itself, and concern quickly spread to the architecturally similar TLS 1.0/1.1. PCI DSS, the payment card industry's security standard, announced a phased ban on TLS 1.0 in 2015 and set June 2018 as the deadline for a complete migration away from TLS 1.1 and below.
TLS 1.3, standardized in 2018, learned from these past vulnerabilities by removing cipher suites prone to weaknesses (such as RC4 and CBC-mode block ciphers) and cutting down the number of handshake round trips. Today, most major browsers and server software enable TLS 1.3 by default and have already dropped support for TLS 1.0/1.1.
Even so, servers that still depend on legacy systems exist worldwide, and it is not uncommon to find TLS 1.0/1.1 left enabled unnoticed. Making a server's configuration easy to see at a glance — something administrators can otherwise overlook — is exactly the value a diagnostic tool like this one provides.