🔒 TLS Version Checker
Check which TLS/SSL protocol versions are supported by any website or domain.
Which versions still count
The domain is contacted live from our server, so the answer describes the host as it stands today rather than anything you pasted. Five protocol versions can come back, and only two of them belong on a public site:
SSL 2.0 / 3.0 dead; broken by POODLE in 2014
TLS 1.0 (1999) deprecated by RFC 8996, dropped by browsers in 2020
TLS 1.1 (2006) same
TLS 1.2 (2008) the floor - keep it for older clients
TLS 1.3 (2018) one round trip, and the weak options removed outright
A client and server negotiate the highest version both offer, so leaving 1.2 and 1.3 on together costs nothing - modern browsers take 1.3 regardless.
What this does not tell you
- Version is not cipher strength. TLS 1.2 covers everything from a solid AEAD suite to a creaky CBC one; the version list says nothing about which the server prefers.
- It tests the public HTTPS endpoint. Mail, database and admin
ports have their own settings - check those with
openssl s_client -connect host:465 -tls1_2. - Behind a CDN, you are testing the edge. Cloudflare or CloudFront may present TLS 1.3 while your origin still answers 1.0 on its own address.
ssl_protocols TLSv1.2 TLSv1.3; and Apache
SSLProtocol -all +TLSv1.2 +TLSv1.3. Reload, then re-check here.Frequently asked questions
Should I turn off TLS 1.0 and 1.1?
For a normal website, yes - no current browser will ask for them, and PCI DSS has required 1.0 to be off since 2018. Look at your access logs first if you serve embedded devices, payment terminals or Android 4.3 and older, which have no 1.2 support.
Is supporting an old version the same as being vulnerable?
No. Offering TLS 1.0 does not expose a modern browser, which negotiates 1.2 or 1.3 anyway. It is a compliance failure and it leaves older clients on weak cryptography, which is reason enough to remove it.
Do I need to do anything to get TLS 1.3?
Usually just a current server build: OpenSSL 1.1.1 or newer, with nginx 1.13+ or Apache 2.4.37+. It is enabled by naming TLSv1.3 in the protocol list; no certificate change is involved.