Certificate & encryption
Check a site's SSL/TLS security
Enter a domain to inspect its certificate, encryption protocol, certificate chain, and HTTPS hardening — and get an overall grade.
How this check works
- Cactus opens a TLS connection to the host on port 443 to read its certificate and the negotiated protocol. The site operator can see Cactus's IP in that connection.
- Cactus makes one HTTPS request to read the site's security headers (such as HSTS).
- Nothing you enter is stored. Enter just a domain — not a full URL containing private tokens.
Overall grade
cactus.net
TLS 1.3
· TLS_AES_256_GCM_SHA384
A+
TLS grade
Why this grade
- No issues detected — a strong TLS configuration.
Connection
Negotiated encryption
- Protocol
- TLS 1.3
- Cipher suite
- TLS_AES_256_GCM_SHA384
- Forward secrecy
- Yes
- TLS 1.3
- Supported
- TLS 1.2
- Supported
- TLS 1.0/1.1
- Not negotiable (refused by the server, or no longer testable from modern systems)
Certificate
cactus.net
- Common name
- cactus.net
- Matches the host you entered
- Yes
- Alternative names
- cactus.net, *.cactus.net
- Issued by
- WE1
- Public key
- ECDSA 256-bit
- Signature
- sha256ECDSA
- Valid from
- 2026-08-14
- Valid until
- 2026-11-12
- SHA-256 fingerprint
00BBAD36B8ED13F8FE9D3B19C54C37560D13E6FC5B3209119028A3FA389BFDB8
Certificate chain
Chain is trusted
- Leaf cactus.net
- Intermediate WE1
- Intermediate GTS Root R4
- Root GlobalSign Root CA
HTTPS hardening
Security posture
- Present
- Certificate Transparency
- Present
- Revocation
- Good
Important limitation
Cactus reports the protocol and cipher actually negotiated with your connection, not every combination the server supports, and it does not probe for specific vulnerabilities (e.g. Heartbleed, POODLE).