Free tool · Coming soon

TLS & Cache Checker.Certificates, protocols, cache: one pass.

Certificate chain, protocol versions and cache behavior verified in a single pass, including the check that matters most this decade: whether your certificate operations are ready for the industry’s shortening lifetimes, stepping down from 200 days in 2026 toward 47 days by 2029.

AT A GLANCETLS & Cache Checker
IN DEVELOPMENT
In buildpart of the first wave
Freeno signup required
47-daycert-era readiness check
TLS 1.3protocol & cipher posture
HIT/MISSreal cache behavior probes
2026launch window
Part of the CDN World toolkit · first releases in build, July 2026
Freeto use, forever
No signuprequired to run it
Shareableevidence-backed reports
In buildfirst releases, 2026
Measured in your browserWe advise on speed. We practice it.Loaded just now · real numbers from this visit, not a lab score.
Page loaded
First byte
DOM ready
First paint
Largest paint
DNS lookup
TLS handshake
Transferred
Saved by compression
Requests
What it answers

TLS & Cache Checker in four questions.

Is the certificate estate healthy

Chain validity, expiries, issuer posture, and whether renewal automation is in place for the shortening-lifetime era.

Is the TLS configuration modern

Protocol versions and negotiation, is the edge serving TLS 1.3 to clients that speak it?

Is caching actually happening

Repeat-request probes show real HIT/MISS behavior per asset class, not what the config file claims.

Are you ready for 47-day certificates

Lifetimes step down from March 2026; manual renewal processes stop being survivable. The checker grades your readiness.

Under the hood

How it works.

The same signals our analysts use in paid assessments, automated.

DETECTIONHow it works
TLS handshake probes · protocols & chain

Handshakes at multiple protocol versions capture what the edge actually negotiates, and the full chain it presents.

Core
Chain validation · trust & expiry

Every certificate in the chain checked for validity, expiry windows and known-problem issuers.

Core
Repeat-request cache probing · observed, not claimed

Sequenced requests reveal true cache behavior: HIT, MISS, and the TTLs actually honored at the edge.

Core
Lifetime-policy timeline · 2026–2029 readiness

Expiries and renewal patterns are graded against the industry’s published lifetime reduction schedule.

Core
The report

What you’ll get.

THE OUTPUTInside the report
Chain & expiry map

Every certificate, its validity and its renewal deadline.

Included
Protocol matrix

What was negotiated at each attempted version.

Included
Cache verdicts

HIT/MISS behavior per asset class, with honored TTLs.

Included
Shortening-lifetime readiness

A grade on whether your renewal operations survive 47-day certificates.

Included
Use cases

Who it’s for.

Teams facing the 2026 step-down

Certificate lifetimes begin shortening in March 2026; this is the readiness check.

Cache-hit tuning

Find the asset classes silently missing cache before the bandwidth bill does.

Compliance checks

Chain and protocol posture, documented in a shareable report.

Migration verification

Prove the new edge negotiates and caches the way the old one did, or better.

Status & early access

Free at launch. In build now.

STATUSWhere the build stands
IN DEVELOPMENT
Freeat launch, no signup
2026launch window
200+assessments/yr behind the data
Earlyaccess list open now
Built on assessment data

The toolkit automates the detection and benchmark data behind the assessments we already run, the tools are how we prove the data is good.

Free, no signup, shareable

Every tool ships free with shareable reports; the business model is the advisory behind it, not your email address.

In development now

First releases are in build. Dates are windows, not promises, we ship when the detection is trustworthy.

UNTIL IT SHIPSGet early access →

Want the answer before the tool exists? A free assessment runs the same analysis, human-graded, usually within 24 hours, and puts you on the early-access list for TLS & Cache Checker.

Status as of July 2026 · join the list and we’ll notify you at launch
FAQ

TLS & Cache Checker questions,
answered straight.

When does the checker launch?

It’s in development in the first toolkit wave, 2026 launch window; the tools page has the early-access list.

What’s the 47-day certificate story?

The CA/Browser Forum has scheduled maximum certificate lifetimes to step down from today’s 398 days to 200 days in March 2026, then 100 days in 2027, reaching 47 days by March 2029. Manual renewal doesn’t survive that; the checker grades whether your automation will.

How does it test caching without my logs?

Sequenced repeat requests observe the edge’s actual HIT/MISS responses and honored TTLs per asset class, behavior, not configuration claims.

Will it flag weak ciphers?

Protocol and negotiation posture is in the launch scope, graded against current guidance rather than exhaustive cipher enumeration.

Is it safe to run against production?

Yes, it’s a handful of ordinary HTTPS requests, indistinguishable from a browser visit.

I need this checked today.

A free assessment covers TLS and cache posture, human-graded, usually within 24 hours.