Free TLS/SSL Security Test
Free tool
Checks TLS versions, cipher suites, certificate chain, OCSP stapling, and HSTS against your live domain. Flags weak configs with the exact fix to apply.
- HTTPS verification
- HSTS check
- TLS version check
- Cipher suite analysis
- Mixed content detection
No credit card requiredRead-only, no exploitationNo setup or code required
Used by 5,000+ developers and engineering teams








What you get for free
18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.
What Essential adds from €199/mo
Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.
What this test checks
TLS Version Support:
- TLS 1.2 and TLS 1.3 support
- The protocol version your server negotiates
Certificate Validation:
- Certificate chain and CA trust
- Hostname matching with SAN and CN verification
- Certificate expiry dates
Cipher Suite:
- The cipher suite your server negotiates with a modern client
- Whether it's an AEAD cipher (AES-GCM, ChaCha20-Poly1305) or a CBC suite
- It doesn't list every suite your server accepts, so use a full TLS scanner for that
Security Features:
- Whether your server staples an OCSP response
- Certificate expiry recommendations with time-based scoring
TLS Security Best Practices
Protocol Configuration:
- Enable TLS 1.2 and 1.3, disable 1.0 and 1.1
- Configure proper cipher suite order by strength
- Implement HSTS with appropriate max-age and includeSubDomains
Certificate Management:
- Use certificates from trusted Certificate Authorities
- Implement proper certificate chain validation
- Set up automated certificate renewal and monitoring
- Configure CAA records to control certificate issuance
Performance Optimization:
- Enable OCSP stapling for faster certificate validation
- Use modern AEAD ciphers for better security and speed
- Monitor certificate expiry dates proactively
How to improve TLS security
Server Configuration:
- Update server software to latest stable version
- Configure SSL/TLS settings in web server (Apache, Nginx, IIS)
- Use security configuration generators (Mozilla SSL Config Generator)
- Test configuration with multiple TLS testing tools
Certificate Improvements:
- Obtain certificates from reputable CAs (Let's Encrypt, DigiCert)
- Implement automated certificate renewal
- Add CAA records to control certificate issuance
- Monitor certificate expiry dates proactively
Security Monitoring:
- Set up automated certificate expiry monitoring
- Configure security monitoring and alerting
- Regular TLS configuration reviews and testing
Implementation examples
Once you've identified the gap, applying the fix is straightforward. Here are the three configurations developers reach for most often.
Nginx
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
ssl_ecdh_curve X25519:secp384r1;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
ssl_stapling on;
ssl_stapling_verify on;Apache
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
SSLHonorCipherOrder off
SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305
SSLSessionTickets off
SSLUseStapling on
SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"Tool-specific questions
What is a TLS security test?
A TLS security test validates your website's SSL/TLS configuration: supported protocol versions (e.g. TLS 1.2, 1.3), cipher suites, certificate chain, OCSP stapling, and HSTS. Weak or misconfigured TLS can lead to downgrade attacks or compliance failures. Barrion's free tool checks your domain and returns actionable recommendations to meet modern TLS best practices.
What's the difference between TLS 1.2 and TLS 1.3?
TLS 1.3 offers improved security, faster handshakes, and better performance. It removes legacy features like compression and renegotiation, uses only AEAD ciphers, and reduces the number of round trips. TLS 1.2 is still widely supported and secure when properly configured.
What's the difference between strong and weak key exchange methods?
Strong key exchange methods like ECDHE and DHE use ephemeral keys that provide forward secrecy, while weak methods like RSA, DH, and ECDH use static keys.
What are AEAD ciphers and why should I use them?
AEAD (Authenticated Encryption with Associated Data) ciphers provide both encryption and authentication in a single operation. They're more secure and efficient than traditional ciphers, preventing padding oracle attacks and providing better performance. Examples include AES-GCM and ChaCha20-Poly1305.
How often should I check my TLS configuration?
Regular TLS configuration reviews are essential. Check after server updates, certificate renewals, or security patches. Use Barrion's continuous monitoring to track TLS changes over time and receive alerts for any security regressions.
What's the impact of weak cipher suites?
Weak cipher suites can expose your communications to various attacks including man-in-the-middle, padding oracle attacks, and brute force attempts. They also impact performance and may not provide adequate encryption strength for sensitive data.
What makes a cipher suite secure?
Secure cipher suites use strong encryption algorithms (AES, ChaCha20), modern key exchange methods (ECDHE, DHE), strong authentication (ECDSA, RSA), and secure MAC/AEAD modes (GCM, Poly1305, SHA256/384). Avoid RC4 and 3DES, and prefer AEAD suites over CBC.
What's the difference between OCSP and OCSP stapling?
OCSP (Online Certificate Status Protocol) requires clients to check certificate revocation status with the CA, while OCSP stapling allows the server to provide the revocation status directly. Stapling improves performance, reduces CA server load, and enhances privacy by not exposing client IPs to CAs.
How do I choose the right certificate authority?
Consider factors like trust level, validation process, support quality, pricing, and automation capabilities. Let's Encrypt offers free automated certificates, while commercial CAs like DigiCert provide extended validation and support. Choose based on your security requirements and budget.
What does the cipher check include?
It reads the cipher suite your server negotiates with a modern client and flags CBC suites as weak. It doesn't enumerate every suite your server accepts, so use a full TLS scanner if you need that list.
Why Barrion
Built for the engineers who already have enough to fix.
Speed
Fast results
Instant analysis with a detailed report. You see findings as the scan runs, not after.
Coverage
Comprehensive checks
The full passive scan runs 18 checks on the free plan, covering TLS, headers and cookies. Paid plans run 35+ and add CORS, DNS, email auth and more.
Action
Step-by-step fixes
Every finding ships with the exact remediation step for your framework. Hand it to the engineer who owns the surface.
Other tools
More free checks, for the rest of your surface.
Complete Security Scan
Complete website security analysis with comprehensive vulnerability detection
Pre-Pentest Security Scan
Passive scan that catches the misconfigurations a pentester finds first. Use it before a manual engagement to clear the easy issues.
Security Compliance Checker
Run general security checks relevant to PCI DSS, HIPAA, SOC 2, ISO 27001 and GDPR. Findings aren't mapped to specific requirements.
WAF Checker
Detect which WAF or CDN sits in front of your site from the signatures in its response. Passive, no attack payloads.
Security Headers Test
Check your website's HTTP security headers configuration
Content Security Policy (CSP) Checker
Analyze your CSP for unsafe directives and strengthen your policy with best practices.
Related guides
Go deeper on the same topic.
Learn
Tls Security
Per-check explainer covering what it is, why it matters, and how Barrion verifies it.
Fix guide
Weak Tls Protocols
Step-by-step remediation with config examples for Nginx, Apache, and Node.
Fix guide
Certificate Expiry
Step-by-step remediation with config examples for Nginx, Apache, and Node.
FAQ
Frequently asked.
What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will our auditor or enterprise customer accept the report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we store the findings and the evidence behind them, the requests and responses that confirm each issue, so you can review and reproduce them. Test credentials you add are encrypted. Data is stored and hosted in Sweden and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.
Anything else? Email contact@barrion.io.