tls-v1-0.badssl.com

Scanned 3 days ago · Sep 3, 2026, 9:33 PM

B

TLS & Certificate

Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.

Score75%
  • the server does not support TLS 1.3
  • the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
  • no Strict-Transport-Security (HSTS) header
NegotiatedTLSv1.2, ECDHE-RSA-AES128-GCM-SHA256
Forward secrecyYes
HSTSnot enabled

Citrix 2026 protocol baseline

NoTLS 1.3 enabled
YesTLS 1.2 enabled
YesTLS 1.1 disabled
YesTLS 1.0 disabled

Cipher suites probed

Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - "accepted" means the server completed a handshake using it, not merely that it's listed as a possibility.

ECDHE-ECDSA-AES256-GCM-SHA384
SecureNot offered
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureNot offered
ECDHE-RSA-CHACHA20-POLY1305
SecureNot offered
DHE-RSA-AES256-GCM-SHA384
SecureAccepted
DHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES256-SHA384
WeakAccepted
ECDHE-RSA-AES128-SHA256
WeakAccepted
AES256-GCM-SHA384
WeakAccepted
AES128-GCM-SHA256
WeakAccepted
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered

Certificate

Subject*.badssl.com
IssuerYR2
Additional names*.badssl.com, badssl.com
ValidJul 28, 2026, 8:03 PM – Oct 26, 2026, 8:03 PM (expires in 53 days)
KeyRSA 2048 bit
Signature algorithmunknown
SHA-256 fingerprint68:8F:99:18:5E:12:A4:94:D3:91:0C:E0:60:53:28:26:A3:5F:E0:24:76:E1:7E:9B:AD:2F:68:E9:23:84:7C:A3
Certificate chain4 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo

Security Headers

The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.

Scoren/a
  • could not fetch https://tls-v1-0.badssl.com/

Email

Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.

Scoren/a
  • no mail servers (MX records) found for this domain