TLS Version Scanner
See which TLS versions a server actually supports, catch deprecated TLS 1.0 and 1.1, and check the negotiated cipher — in seconds, with no signup.
Why old TLS versions are a liability
TLS is the protocol behind the padlock in your browser, and not every version is safe. TLS 1.0 and 1.1 are deprecated — the PCI Council and every major browser have dropped them because of known weaknesses. If your server still accepts them, an attacker can try to force a client down to the weaker protocol.
TLS 1.2 and 1.3 are the current safe versions, with 1.3 being faster and stripping out legacy cipher options entirely. This scanner shows exactly which versions your server allows so you can confirm the old ones are switched off and the modern ones are on.
What this TLS scanner checks
Enter a domain and the tool opens real TLS handshakes, one per protocol version, to see which the server accepts. It then reads the cipher your server negotiates by default and pulls a short certificate summary — expiry, issuer, and days remaining — so you get the security picture in one view.
It's a read-only inspection: it completes the handshake, records the result, and disconnects without exchanging any data. Note that a runtime may be unable to even offer TLS 1.0/1.1, in which case that row is marked 'not testable' rather than guessed.
How do I check which TLS version a site uses?
Enter the domain above and run the scan. The tool attempts a handshake for each TLS version — 1.0, 1.1, 1.2 and 1.3 — and shows which the server supports, plus the protocol and cipher it negotiates by default.
Is TLS 1.0 or 1.1 still safe to use?
No. TLS 1.0 and 1.1 are deprecated and considered insecure; browsers and payment standards have removed support. If this scanner shows them as enabled, you should disable them on your server and keep only TLS 1.2 and 1.3.
What is the negotiated cipher?
When a client and server connect, they agree on a cipher suite — the exact set of algorithms used to encrypt the session. The tool shows the cipher your server picks by default, which tells you whether it prefers strong, modern encryption.
Can Narvin watch my TLS configuration over time?
Yes. Narvin continuously monitors your certificate and TLS setup and alerts you before a certificate expires or if your protocol support regresses — so a security downgrade or a missed renewal never slips through unnoticed.
Put every site you answer for under watch.
First monitor live in under a minute. No credit card, 5 monitors free, forever.
Start monitoring free