Frequently asked questions
About the checker, grades and fixing common TLS problems.
What does sslverify.net check?
For any public host it checks the certificate (validity, days left, hostname match, key and signature), the chain of trust against the Mozilla root store, TLS 1.0–1.3 support, every accepted cipher suite in the server's order, post-quantum key exchange (X25519MLKEM768), OCSP stapling, ALPN, HSTS and the HTTP → HTTPS redirect. The results add up to a grade from A+ to F.
How is the grade calculated?
Every site starts at A and each problem caps the grade. An untrusted, expired or mismatched certificate gives F. Insecure ciphers (RC4, 3DES) or a server without TLS 1.2/1.3 cap it at C. TLS 1.0/1.1, ciphers without forward secrecy or an incomplete chain cap it at B. A clean A with an HSTS policy of at least 180 days becomes A+. Post-quantum support is shown separately and doesn't change the grade yet.
Why does my site get a B?
The most common reasons are deprecated TLS 1.0/1.1 still being enabled, cipher suites with plain RSA key exchange (no forward secrecy), or a missing intermediate certificate. The findings list under the grade tells you exactly which one applies. If you use Cloudflare, set SSL/TLS → Edge Certificates → Minimum TLS Version to TLS 1.2.
What is post-quantum TLS and do I need it?
Post-quantum TLS uses a hybrid key exchange (X25519MLKEM768) that stays secure even against future quantum computers. It protects against harvest now, decrypt later, where traffic recorded today is decrypted years from now. If your users send data that must stay confidential for years, you should enable it. Read our explainer.
My site works in the browser. Why does the chain show as incomplete?
Browsers quietly download missing intermediate certificates, but curl, Java, Python, Android apps and API clients don't. Serve the full chain (fullchain.pem) to fix it. See the full guide.
Can I check a port other than 443?
Yes. Enter host:port, e.g. example.com:8443 or mail.example.com:993. The port must speak TLS directly; STARTTLS (SMTP on 587, IMAP on 143) isn't supported yet.
Can I check internal or private servers?
No. For security reasons only hosts that resolve to public IP addresses can be checked. Private ranges, localhost and similar addresses are refused.
Do you store the results?
Results are kept in memory for 5 minutes so repeated checks are instant, then discarded. Use “Run a fresh check” to bypass the cache. We don't keep a history of checked domains.
Is there an API?
Not publicly. The checker is meant to be used through the website. If you need automated or bulk monitoring, contact us.
Can you fix my configuration for me?
Yes. We offer one-off TLS and certificate fixes, post-quantum readiness reviews and managed Cloudflare security. Request a free consultation.