SSL Labs

Our check is whether a page arrived over HTTPS at all. SSL Labs opens the handshake and grades the certificate, protocols and ciphers behind it.

Why our report names it

Our HTTPS check is close to a single line of the scanner: whether the address we finished on begins with https. Everything the padlock actually rests on, whether the chain is trusted, which protocol versions the server still negotiates, which ciphers it will accept, sits behind a handshake we never inspect. Our own knowledge base sends you to an SSL checker for exactly that and names SSL Labs, and this entry is that recommendation with the overlap stated rather than glossed over.

What it doesn't do

  • It stops at the transport and says so in writing. The rating guide carries a section on what it does not cover, which states that a cookie left without the Secure attribute can be lifted by a determined attacker, that detecting web-application problems automatically is hard, and that this version does not attempt it. Our scan does read cookie attributes, response headers, indexing tags and accessibility rules on that same page in that same run. Depth on one thing against breadth in one pass: neither of us replaces the other.
  • Where we do overlap, be clear which of us goes further. We both look at HSTS, and where our scan compares the max-age value against 15,552,000 seconds and returns pass or fail, SSL Labs applies its published rule and moves a letter grade. On the certificate itself there is no contest at all, because we never read it.
  • Results are published by default. The SSL Server Test page carries public boards of recently tested hostnames and of the highest and lowest grades it has lately handed out, and the box that keeps yours off them sits unticked until you tick it, so an unthinking first test of a staging hostname is a disclosure.
  • One hostname, one endpoint, one moment. A host that is not on the public internet cannot be reached at all, which rules out anything behind a VPN, and a grade earned this morning says nothing about the certificate that renews in three months.

What it does

  • Qualys publishes the method, which is the part worth having. The rating guide sets out four steps: confirm the certificate is valid and trusted, score protocol support, key exchange and cipher support, combine those into one number where a zero in any category takes the total to zero, then apply named rules that shift the letter grade either way.
  • Because those rules are published and versioned, an SSL Labs grade is arguable rather than oracular: its 2025 revision records that a server without TLS 1.3 has its protocol grade capped, and that HSTS disabled or invalid pulls the grade to A-, so you can read why you got what you got.
  • It runs from outside your network, against any server reachable on the public internet, which means it sees the certificate chain your visitors' browsers see rather than the one your own workstation happens to already trust.

More on the problem

Nothing here is gated behind us. Go straight to SSL Labs and make your own mind up.

Go to SSL Labs

Sources

Every claim about SSL Labs on this page was read on from the pages below. Products change and this page does not change with them, so treat the date as the claim's expiry rather than its publication.

Ready to see where you stand?

Scan your site and get your Engineering Score with a prioritized roadmap in under a minute, no signup required.

Scan your site