Post-Quantum Checker

Unified TLS, DNSSEC, and DNS transport readiness check

Run a unified readiness check for post-quantum TLS, DNSSEC validation, and DNS transport behavior on public domains.

Public Internet targets only. Localhost, private IP ranges, link-local addresses, reserved networks, and metadata endpoints are blocked.

This unified checker combines Post-Quantum TLS, DNSSEC validation, and DNS transport signals into READY, PARTIALLY READY, NOT READY, or UNKNOWN.

Post-Quantum Checker Tester

Port.Tools and more available on mobile:

What this Post-Quantum Checker tests

The unified checker combines TLS and DNSSEC signals for a public domain. It checks TLS 1.3 and X25519MLKEM768 readiness, DNSSEC validation, DNSKEY, DS, RRSIG records, and DNS transport behavior.

How to improve readiness

Enable TLS 1.3, use hybrid post-quantum key exchange such as X25519MLKEM768 where available, maintain valid DNSSEC signing, and verify DNSKEY responses over both UDP and TCP after DNS or TLS changes.

FAQ

What does READY mean?

READY means the checked signals indicate support for the expected TLS or DNSSEC capability. PARTIALLY READY means some signals pass while others still need configuration or provider support.

Why check TLS and DNSSEC together?

Post-quantum readiness is broader than one TLS handshake. TLS key exchange, DNSSEC signatures, DNSKEY responses, and DNS transport behavior all affect how a public domain prepares for quantum-safe infrastructure.