Enter a hostname, optionally with a port such as mail.example.com:993, to see which TLS versions the server accepts. Each version is tried on its own, so you can confirm that TLS 1.2 and 1.3 work and the deprecated TLS 1.0 and 1.1 are switched off.
Table of Contents
Which versions to allow
TLS 1.2 and TLS 1.3 are the only versions that should be enabled. TLS 1.0 and 1.1 were formally deprecated in RFC 8996, browsers dropped them years ago and PCI DSS does not allow them. TLS 1.3 is faster to connect and removes weak ciphers entirely; it needs OpenSSL 1.1.1 or newer.
Turning off old TLS on cPanel and DirectAdmin
On cPanel, set the SSL/TLS protocols in WHM Apache Configuration, Global Configuration, and check Exim, Dovecot and cpsrvd separately because each service has its own setting. On DirectAdmin the web server, Exim and Dovecot each have an SSL protocol option in their configuration. After changes, test every port: web 443, SMTP 465, IMAP 993, POP3 995 and the panel ports.
HTTP/2 and the certificate
For web ports the checker also reports the HTTP version negotiated through ALPN and the certificate subject, issuer and expiry, so one test shows whether the HTTPS setup is modern end to end.
TLS Version Checker at a glance



Official documentation: RFC 8996 (deprecating TLS 1.0 and 1.1), RFC 8446 (TLS 1.3), Mozilla SSL configuration generator.
Related guides: cPanel SSL/TLS Interface (v136+): Easy Install and Renew · DirectAdmin ACME TLS Migration (1.706+): Safe Step-by-Step Plan · 47-Day SSL Certificate Lifetime: Critical Automation for Hosts.
Frequently asked questions
Will disabling TLS 1.0 and 1.1 break anything?
Only very old clients, such as Android 4.3 and earlier or unpatched Windows 7 software, still need them. Old mail clients and scanners or printers that send mail are the usual exceptions, so test them before switching off old TLS on mail ports.
Why is TLS 1.3 not supported on my server?
The OpenSSL library is older than 1.1.1, or TLS 1.3 is not in the protocol list of the web or mail server. Current AlmaLinux, Rocky and Debian releases support it out of the box.
Why is SSL 3.0 not tested?
Modern TLS libraries cannot offer SSL 2.0 or 3.0 at all, and no current server should accept them.