Deep TLS Configuration Scanner
Transport Security Diagnostic
Deep TLS Configuration Scanner
Perform real TLS handshakes against port 443 to test protocol support, inspect the negotiated cipher, certificate validity, SAN data and the certificate chain.
A certificate checker and a TLS scanner answer different questions
A valid certificate proves very little about which protocol versions the server will accept. This scanner makes separate handshakes for TLS 1.0, 1.1, 1.2 and 1.3 so obsolete protocol support cannot hide behind a successful modern connection.
It still does not claim to be SSL Labs in miniature. It records the cipher negotiated by each successful probe rather than attempting exhaustive cipher-suite enumeration, and network-edge/CDN behaviour can vary geographically. The output is evidence for configuration review, not a universal grade.
