Tools Learn Pricing Login Sign up
New securityheaders.com shut down its free API — we built a compatible replacement. Migrate in one line →
SSL · Email · Headers — one civil scan

Free SSL checker.
Know your site's security in seconds.

Test your SSL/TLS certificate, HTTP security headers and email authentication (SPF, DKIM, DMARC) — and get a plain-English A+ to F grade, no signup. Then keep watch from one dashboard: certificate lifecycle, header grades and uptime, with alerts where your team already works. No sales call. Just receipts.

Scan scope Free · no signup
TLS, headers, email security and Certificate Transparency in one report; the TLS deep-scan streams in as it completes.
No signup needed Results in seconds A+ to F grading
Why MySSL

Everything you need to keep TLS healthy — and everything around it.

Built for engineers and security teams who want straight answers — not vendor dashboards. Scan once free, or wire up monitoring for certificates, headers, uptime and email in two clicks.

New · Blastline

Scanners stop at the door. Blastline starts inside.

A grade of A+ says nothing about the .env sitting at 0644 that every app on the box can read. Blastline is a one-way Linux agent that measures what your server declares, what its apps can reach, and what moved — and writes unknown for everything it can't settle.

Scored against the Linux kernel: 0 false positives, 0 false negatives across the 3,130 queries it answered at high confidence — and it abstained on the other 812 rather than guessing. Hourly and jittered, not real-time. No listening socket: bind()=0 listen()=0 connect()=1. File contents and secret values never leave your host.

One read-only pass · hourly, jittered shop.example.com · illustration, measured figures
  1. I what this server declares route_coverage partial
  2. II what the app's own OS user can reach 17 open / 100 closed
  3. III what moved since the last pass 8 watched / 42 excluded
  4. IV where code could be placed 3 deny / 12 unknown

Four readings, one pass. The hatched share is what the evidence did not settle — reported at full contrast, never rounded away.

Shipping log

What's new

What shipped, when — straight from the commit log.

7 Aug 2026

Blastline — a one-way Linux agent that measures three things about a running web server: what it declares, what each app's own OS user can reach, and what moved since the last pass. Scored against the kernel, with an explicit unknown tier when the evidence does not settle it.

14 Jul 2026

Security-headers monitoring is live end-to-end — schedule re-scans per domain and get grade-drop alerts in Slack, Discord, Telegram, email or webhooks.

14 Jul 2026

API Stability & Longevity Pledge published — versioned endpoints, successor-before-deprecation, 12+ months' notice, machine-readable Deprecation/Sunset headers.

24 Jun 2026

47-day certificate readiness Watchtower + shareable badge — plus subdomain-takeover alerts for monitored domains.

21 Jun 2026

Free Security Headers API — a compatible replacement for the discontinued securityheaders.com API. 40 checks/hour anonymous (400/day), 2,000/day with a free key.

20 Jun 2026

Certificate Transparency Explorer — search CT logs for any domain, plus CT monitoring with new-certificate alerts.

What our SSL checker tests

A complete SSL/TLS & web security test in one scan

Most SSL checkers only look at certificate dates. MySSL.info goes deeper — we run the same checks a professional auditor would, then translate them into plain English.

Frequently asked questions

SSL checker FAQ

Is MySSL.info really free?

Yes — every SSL scan, security header test, SPF/DKIM/DMARC check and tool on this site is free without signup. Optional accounts add continuous monitoring, alert routing and a longer history window.

How is the A+ to F grade calculated?

We grade against the same rubric used by the well-known public TLS test suites — certificate validity, key strength, protocol versions, cipher suites, forward secrecy, and known vulnerabilities — then layer on HTTP security headers and email authentication checks.

Can I scan internal or non-standard ports?

Yes. Add the port in the form (e.g. example.com:8443). Scans work for any host reachable over the public internet.

Will MySSL.info store my scan?

Public scans are cached for 24 hours so repeat checks on the same domain return instantly. With an account, your scan history is stored privately for trend analysis and compliance audits.

How do I get notified before a certificate expires?

Add the domain to your dashboard. We send expiry alerts at 30, 14 and 7 days, then again on the day — via email, Slack, Discord, Telegram or webhook.

Does it support post-quantum cryptography (PQC)?

Yes. The TLS scan detects ML-KEM hybrid key exchange (X25519MLKEM768) on TLS 1.3, and the PQC readiness checker gives a dedicated quantum-safe verdict.

Read the full FAQ →

Report a bug

We're new and growing — your feedback helps us improve.

Click to upload, or paste (Ctrl+V) an image