What we checkCertificate & HTTPSTL-01
HTTPS is reachable
Your site should answer on port 443 with a working TLS handshake.
- Check
- TL-01
- Included
- Free in every scan
What we check
We resolve your domain and www, open a TLS connection to each, and request the homepage.
Why it matters
Everything else in this section depends on this one. A site that does not answer over HTTPS has no certificate to check, no protocols to test, and no security headers to send.
Browsers have defaulted to HTTPS for years; a domain that only answers on port 80 now shows a warning before a visitor sees anything.
It is also the check that most often fails for only half your visitors. A server or certificate configured for the apex but not for www — or the other way round — works perfectly for whoever set it up and shows a warning to everyone arriving from an old link, a printed card, or a habit.
How to fix it
- 1
Confirm your server is listening on 443 and that a firewall is not blocking it.
- 2
Get a certificate — Let's Encrypt issues them free and most hosting platforms automate it entirely.
Common questions
- My site works in my browser. Why does this fail?
- Usually
www— we check both names. A certificate or a server that answers for one and not the other fails for half your visitors. - I use Cloudflare. Does that count?
- Yes. We check what the public internet sees, which is your CDN's connection. That is also what your visitors get.
- Does an IPv6-only site pass?
- Yes. We try A and AAAA records and are satisfied by either.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.