Security Headers
securityheaders.com
Grades the HTTP security headers a site sends and names the missing ones
ssllabs.com
Grades a site's TLS configuration from A+ down to F and says why.
The reference TLS audit: certificate chain, protocol versions, cipher suites, forward secrecy, known vulnerabilities and client compatibility across dozens of browser and OS combinations, ending in a letter grade. The handshake simulation section is the useful part when an old Android or a Java client cannot connect and nobody can explain why. Scans are public by default unless you tick the box, and a full run takes a couple of minutes.
AltFTool does this too
If you would rather not leave the site, SSL Certificate Inspector covers the same job here — free, no account, and it runs in your browser.
Open SSL Certificate InspectorQuestions
Works the moment the page loads. No account, no email, no trial. Results appear on a public board unless you opt out, and it only tests public hosts on port 443.
Yes. Qualys SSL Labs Server Test sends your input to its own servers to process it. That is fine for public material; for anything containing personal data, use one of the on-device tools instead.
Results appear on a public board unless you opt out, and it only tests public hosts on port 443.
Alternatives
Same category or same task, ordered by how closely they overlap.
securityheaders.com
Grades the HTTP security headers a site sends and names the missing ones
pagespeed.web.dev
Scores a page on real-user Core Web Vitals and lab measurements
wave.webaim.org
Overlays accessibility errors directly on top of the page they affect
webpagetest.org
Loads your page from a chosen city and browser and films the result
downforeveryoneorjustme.com
Settles whether a site is actually down or only down for you
lookup.icann.org
The registry's own WHOIS record for a domain, with no upsell