SSL/TLS & Website

TLS version check

Whether your server still accepts retired encryption (TLS 1.0 and 1.1) and whether it offers the current one (TLS 1.3).

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We check which TLS protocol versions your server will negotiate.

Why it matters to your business

No current browser needs TLS 1.0 or 1.1, and PCI DSS and most cyber-insurance questionnaires require them switched off. TLS 1.3 is faster and more secure; not offering it is a small, easy win to collect.

How to fix it

  1. Disable TLS 1.0 and 1.1 in your server, load balancer or CDN settings (Cloudflare: SSL/TLS → Edge Certificates → Minimum TLS Version 1.2).
  2. Enable TLS 1.3.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Read the help article