I built a free tool that deep-checks your site's HTTPS/TLS setup - redirect chain, cert grade, headers, HTTP/3, and more
You enter a domain and it runs a full security stack analysis in one shot: Redirect chain - traces every hop from HTTP to HTTPS, flags mixed content and redirect loops SSL certificate - expiry date, issuer, SANs, grade (A–F), protocol versions (TLS 1.0/1.1/1.2/1.3) Security headers - HSTS, CSP, X-Frame-Options, Permissions-Policy, Referrer-Policy, and more, each rated HTTP/2 & HTTP/3 - detects ALPN negotiation and confirms QUIC via actual UDP connection DNSSEC & CAA - checks if the zone is signed and if CAA records restrict which CAs can issue certs HSTS preload status - tells you if you're on Chrome's preload list (or why you're not) Mixed content scanner - crawls the page and flags any HTTP resources loaded over HTTPS Beyond the one-off check there's also: Bulk check - up to 10 domains at once Cert expiry reminders - email alert before your cert expires Domain monitoring - periodic re-checks with email diff when something changes No account required. API available for automation. Do you find this useful? Looking for feedback. submitted by /u/EveningRegion3373 [link] [留言]