Tools
Practical tools for TLS, HTTPS, and X.509 certificate operations.
Full domain report One check for the lot — DNS, DNSSEC, email, BIMI, CAA and the certificate. Post-quantum readiness Does your server negotiate quantum-safe key exchange (ML-KEM)? Real handshakes, instant verdict. Certificate decoder Decode PEM/DER X.509 certificates: subject, issuer, validity, SANs, and extensions. CSR generator & decoder Generate Certificate Signing Requests in your browser — private keys never leave your device. Certificate chain visualiser Fetch or paste a certificate chain and see the path from leaf to root CA. HTTP/HTTPS tester Check status codes, follow redirects, inspect headers, and measure response times. Security header generator Generate recommended security header configuration for NGINX, Apache, Cloudflare, and IIS. Mixed content detector Find HTTP resources loaded on HTTPS pages before browsers block them. Base64 encoder/decoder Encode and decode Base64 strings — useful for certificate data and PEM files. TLS version comparator Compare TLS 1.0 to 1.3 side by side: security, performance, and browser support. Visual TLS handshake Step through TLS 1.2 and TLS 1.3 handshakes and see what each message does. TLS Academy Plain-English guides to TLS, cipher suites, CSRs, OCSP, and certificate lifecycle.
Protocol-level tools, built for engineers
TLS Studio focuses on the protocol plumbing behind HTTPS: certificate chains, handshakes, security headers, and the encoding formats certificates travel in. Everything that can run in your browser does, so private keys and certificate data never leave your device.
Want a simpler, beginner-friendly certificate check — is it valid, when does it expire — without the protocol detail? Try SSL Studio, another DNS Studio tool.