SSL/TLS & Website

Certificate key and signature check

Whether your certificate uses a key and signature strong enough for today's browsers.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We check the certificate's key size and signature algorithm against current browser requirements.

Why it matters to your business

Weak keys and old signature algorithms are refused by modern browsers and flagged by security questionnaires from insurers and larger customers.

How to fix it

  1. Reissue the certificate with an RSA 2048-bit or larger key, or an ECDSA P-256 key, signed with SHA-256.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Read the help article