Skip to content

What we checkCertificate & HTTPSTL-01

HTTPS is reachable

Your site should answer on port 443 with a working TLS handshake.

Check
TL-01
Included
Free in every scan

What we check

We resolve your domain and www, open a TLS connection to each, and request the homepage.

Why it matters

Everything else in this section depends on this one. A site that does not answer over HTTPS has no certificate to check, no protocols to test, and no security headers to send.

Browsers have defaulted to HTTPS for years; a domain that only answers on port 80 now shows a warning before a visitor sees anything.

It is also the check that most often fails for only half your visitors. A server or certificate configured for the apex but not for www — or the other way round — works perfectly for whoever set it up and shows a warning to everyone arriving from an old link, a printed card, or a habit.

How to fix it

  1. 1

    Confirm your server is listening on 443 and that a firewall is not blocking it.

  2. 2

    Get a certificate — Let's Encrypt issues them free and most hosting platforms automate it entirely.

Common questions

My site works in my browser. Why does this fail?
Usually www — we check both names. A certificate or a server that answers for one and not the other fails for half your visitors.
I use Cloudflare. Does that count?
Yes. We check what the public internet sees, which is your CDN's connection. That is also what your visitors get.
Does an IPv6-only site pass?
Yes. We try A and AAAA records and are satisfied by either.

See how your domain does on this check.

All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.