Post-quantum TLS test

PQC TLS Checker

Test a public website for TLS 1.3 readiness, visible post-quantum key exchange signals, X25519MLKEM768 exposure and downgrade risk. Start with the public endpoint, then use the result to decide whether a wider cryptographic inventory is needed.

Check a Public TLS Endpoint

Enter a domain to check externally visible TLS posture and post-quantum readiness signals. The result can be saved to a free account after the scan.

Loading checker...

What This Checker Looks For

TLS 1.3 foundation

Checks whether the public endpoint can use modern TLS, which is the baseline for current hybrid PQC key agreement work.

Hybrid PQC key exchange

Looks for visible post-quantum key exchange signals such as X25519MLKEM768 where negotiation evidence is available.

Downgrade exposure

Flags older TLS versions and fallback paths that can weaken the value of a future post-quantum deployment.

Browser security controls

Reviews headers such as HSTS and CSP because TLS posture is only one part of a secure public endpoint.

Result interpretation

How to Read a PQC TLS Result

A good PQC TLS result is a starting point, not the whole migration. Public TLS can show whether the edge is modern enough for hybrid key agreement and whether a provider is already exposing post-quantum negotiation signals.

The result should feed a practical worklist: remove downgrade paths, confirm CDN and origin behaviour, identify APIs with long-lived sensitive data, and decide which systems need a cryptographic inventory next.

PQC active

A visible hybrid key exchange signal was detected. Treat this as strong public-endpoint evidence, then check certificates, signatures, APIs and internal systems separately.

TLS 1.3 ready

The endpoint has a modern transport baseline, but no active post-quantum key exchange was visible during the scan.

Classical only

The endpoint appears to rely on classical TLS key exchange. Long-lived sensitive data may need prioritised migration planning.

Downgrade risk

Older protocol support or weak fallback behaviour can undermine migration work even if a provider later enables PQC.

What the Checker Cannot Prove

No external TLS checker can prove that an organisation is fully quantum-safe. It cannot inspect private APIs, database encryption, signing keys, VPNs, device firmware, supplier systems or archived data with long confidentiality lifetimes.

Use this result as the first visible evidence for public endpoints, then move to a cryptographic inventory and migration plan for systems that process regulated, contractual or long-lived sensitive data.

Start With the Public Endpoint

Run the checker, save the result, then decide whether the site needs a free badge, provider changes or a deeper post-quantum migration plan.