[{"data":1,"prerenderedAt":141},["ShallowReactive",2],{"tool-website-security-check-en":3},{"doc":4},{"title":5,"description":6,"link":7,"published":8,"lastReviewed":9,"lede":10,"faq":11,"body":30},"Website Security Check: HTTP security headers, SSL\u002FTLS and PQC readiness","Check a site’s HTTP security headers, SSL\u002FTLS setup, and post-quantum (PQC) readiness. The check reads what the server returns, and every finding comes with a fix.","website-security-check","2026-09-13","2026-09-21","Enter a domain to see what your site exposes to the internet. The check only uses what the server sends back.",[12,15,18,21,24,27],{"q":13,"a":14},"Can I check a site I do not own?","Yes. The site operator may see our scanner in their logs. We record who started the check and keep that record for 90 days, as described in our privacy policy. The form asks you to confirm that the site will be contacted externally.",{"q":16,"a":17},"Why does a repeated check return the same result?","Results are cached for 300 seconds per domain. Checks made during that period return the same report. The page shows that the result is cached and how long remains before you can run a fresh check. The cache cannot be bypassed.",{"q":19,"a":20},"Which port is checked?","Port 443. If you include another port in the domain, it is ignored. Port 80 is contacted only to check whether HTTP redirects to HTTPS.",{"q":22,"a":23},"What does PQC Readiness check?","The key exchange actually negotiated with the server, not the groups it advertises. A hybrid group such as X25519MLKEM768, or a pure ML-KEM group, passes. Certificate signatures are checked by the SSL\u002FTLS module instead.",{"q":25,"a":26},"The result says the key exchange is classical only. How urgent is that?","It is not an emergency, but it is worth including in your next TLS library upgrade. Use a TLS implementation that supports ML-KEM and enable a hybrid group. If the site is behind a CDN, configure it there because TLS terminates at the CDN. Keep a classical group available for clients that do not support PQC yet, and test compatibility before rollout.",{"q":28,"a":29},"Does this replace a penetration test?","No. This check only looks at what the server exposes without authentication. Issues such as broken access control, business-logic flaws, and injection need deeper testing and are part of a penetration test.",{"type":31,"value":32,"toc":133},"minimark",[33,37,40,45,68,72,75,78,81,85,88,108,111,115,118,121,124],[34,35,36],"p",{},"The report shows what an external client can see from your site at the time of\nthe check. It does not inspect your configuration files.",[34,38,39],{},"If the site is behind a CDN or WAF, what the check reads belongs to that layer\nrather than the origin server. The report names the intermediary it detected,\nand every remediation says which layer to apply it at.",[41,42,44],"h2",{"id":43},"what-is-checked","What is checked",[46,47,48,56,62],"ul",{},[49,50,51,55],"li",{},[52,53,54],"strong",{},"HTTP security headers",": HSTS, Content-Security-Policy, X-Frame-Options,\nX-Content-Type-Options, Cache-Control, CORS, cookie flags, the redirect from\nport 80, and server version disclosure.",[49,57,58,61],{},[52,59,60],{},"SSL\u002FTLS",": accepted protocol versions, cipher suites, downgrade protection,\nrenegotiation, compression, and certificate properties including validity,\nchain, hostname coverage, signature algorithm, and key size.",[49,63,64,67],{},[52,65,66],{},"Post-quantum readiness",": the key exchange the server negotiates, reported\nper address.",[41,69,71],{"id":70},"pqc-readiness","PQC Readiness",[34,73,74],{},"No quantum computer breaks TLS today. The concern is encrypted traffic captured\nnow and decrypted later, which is why key exchange upgrades first.",[34,76,77],{},"The check opens a TLS 1.3 connection and records the key-exchange group the\nserver selects, one row per address. A domain can resolve to several servers\nthat do not share a TLS configuration, so the report lists every address it\nreached: one status when they agree, and which addresses lag when they do not.",[34,79,80],{},"A hybrid group such as X25519MLKEM768, or a pure ML-KEM group, passes. The\nstatus comes from the group negotiated in that handshake, never from the list\nthe server advertises, so a server that supports a post-quantum group but\nselects a classical one during the check does not pass.",[41,82,84],{"id":83},"how-to-read-the-result","How to read the result",[34,86,87],{},"Findings use three statuses:",[46,89,90,96,102],{},[49,91,92,95],{},[52,93,94],{},"Needs fixing",": checked and the issue was found.",[49,97,98,101],{},[52,99,100],{},"Passed",": checked and the issue was not found.",[49,103,104,107],{},[52,105,106],{},"Not assessed",": no verdict was possible.",[34,109,110],{},"Not assessed is not a pass. The row explains why no result was available.",[41,112,114],{"id":113},"after-the-result","After the result",[34,116,117],{},"Each finding includes what to change and, where possible, a command to verify\nthe fix.",[34,119,120],{},"If the setting cannot be changed at the layer you control, the finding points to\nthe layer that needs to be updated instead.",[34,122,123],{},"If your organisation falls under the Website Security Standard B.E. 2568 (2025),\nthis check does not map findings to the clauses in that standard.",[34,125,126,127,132],{},"Use the ",[128,129,131],"a",{"href":130},"\u002Ftools\u002Fwss-2568","self-assessment for that standard"," instead.",{"title":134,"searchDepth":135,"depth":135,"links":136},"",2,[137,138,139,140],{"id":43,"depth":135,"text":44},{"id":70,"depth":135,"text":71},{"id":83,"depth":135,"text":84},{"id":113,"depth":135,"text":114},1790565613404]