Certificate & encryption

Check a site's SSL/TLS security

Enter a domain to inspect its certificate, encryption protocol, certificate chain, and HTTPS hardening — and get an overall grade.

How this check works
  • Cactus opens a TLS connection to the host on port 443 to read its certificate and the negotiated protocol. The site operator can see Cactus's IP in that connection.
  • Cactus makes one HTTPS request to read the site's security headers (such as HSTS).
  • Nothing you enter is stored. Enter just a domain — not a full URL containing private tokens.

You're viewing a shared result.

Overall grade

cactus.net

TLS 1.3 · TLS_AES_256_GCM_SHA384

A+

TLS grade

Why this grade
  • No issues detected — a strong TLS configuration.

Connection

Negotiated encryption

Protocol
TLS 1.3
Cipher suite
TLS_AES_256_GCM_SHA384
Forward secrecy
Yes
TLS 1.3
Supported
TLS 1.2
Supported
TLS 1.0/1.1
Not negotiable (refused by the server, or no longer testable from modern systems)

Certificate

cactus.net

Common name
cactus.net
Matches the host you entered
Yes
Alternative names
cactus.net, *.cactus.net
Issued by
WE1
Public key
ECDSA 256-bit
Signature
sha256ECDSA
Valid from
2026-08-14
Valid until
2026-11-12 · 69 days left
SHA-256 fingerprint
00BBAD36B8ED13F8FE9D3B19C54C37560D13E6FC5B3209119028A3FA389BFDB8

Certificate chain

Chain is trusted

  1. Leaf cactus.net
  2. Intermediate WE1
  3. Intermediate GTS Root R4
  4. Root GlobalSign Root CA

HTTPS hardening

Security posture

Present · max-age=31536000 · includeSubDomains · preload
Certificate Transparency
Present
Revocation
Good · OCSP · CRL
Important limitation

Cactus reports the protocol and cipher actually negotiated with your connection, not every combination the server supports, and it does not probe for specific vulnerabilities (e.g. Heartbleed, POODLE).