TLS Version Checker

Test which TLS versions (1.0, 1.1, 1.2, 1.3) a server accepts and spot outdated protocols.

What is TLS?

TLS (Transport Layer Security) is the encryption protocol behind HTTPS. Versions 1.2 and 1.3 are secure; versions 1.0 and 1.1 are deprecated and should be disabled on every server.

TLS versions at a glance

VersionStatus
TLS 1.3Recommended — fastest handshake, strongest security
TLS 1.2Secure and still required for older clients
TLS 1.1Deprecated (RFC 8996) — disable
TLS 1.0Deprecated (RFC 8996) — disable

How the test works

The checker opens a separate connection to port 443 for each version, offering only that version, and records whether the server accepts it and which cipher it chooses.

Disabling old versions

  • nginx: ssl_protocols TLSv1.2 TLSv1.3;
  • Apache: SSLProtocol -all +TLSv1.2 +TLSv1.3
  • CDNs: set the minimum TLS version to 1.2 in the dashboard.

Check the certificate itself with the SSL Certificate Checker.

Frequently asked questions

Why should TLS 1.0 and 1.1 be disabled?

They have known weaknesses, all modern browsers have dropped them, and PCI DSS compliance does not allow them.

Will disabling TLS 1.0 break anything?

Only very old clients such as Android 4.3 or Internet Explorer on Windows XP are affected.

Is TLS the same as SSL?

TLS replaced SSL. People still say "SSL certificate", but modern HTTPS always uses TLS.