Is your website ready for quantum computers?
Check whether a domain's TLS uses post-quantum key exchange (X25519MLKEM768 / ML-KEM), which groups it prefers, what its certificate uses, and whether HSTS is set. Real handshakes, results in seconds.
Try: google.com · github.com · wikipedia.org
What the checker looks at
Each check is a real TLS 1.3 or 1.2 ClientHello sent from our server. We read the server's answer and hang up before any application data is exchanged.
Post-quantum key exchange
Does the server accept X25519MLKEM768, the hybrid group browsers now send by default? We also try SecP256r1MLKEM768, SecP384r1MLKEM1024 and pure ML-KEM.
Group preference
When a client offers both classical and post-quantum groups, which one does the server pick? A server that picks X25519 leaves those clients unprotected.
Legacy drafts
Is the pre-standard X25519Kyber768Draft00 still enabled? Browsers removed it once ML-KEM was final in FIPS 203.
TLS versions
Post-quantum key exchange exists only in TLS 1.3. We note whether TLS 1.2 is still on for older clients.
Certificate
Key type and size, signature algorithm, issuer and expiry, read from the TLS 1.2 handshake where the certificate is sent unencrypted.
HSTS
Without Strict-Transport-Security, a first visit can be downgraded to plain HTTP, and then no key exchange protects it at all.
How to enable post-quantum TLS
You need a TLS library with ML-KEM support. Then list X25519MLKEM768 first and keep classical groups as a fallback for older clients. Checked against the upstream docs on 29 September 2026; test on staging first.
nginx (built with OpenSSL 3.5 or later)
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ecdh_curve X25519MLKEM768:X25519:prime256v1:secp384r1;
Apache httpd (mod_ssl with OpenSSL 3.5 or later)
SSLProtocol -all +TLSv1.2 +TLSv1.3
SSLOpenSSLConfCmd Groups X25519MLKEM768:X25519:prime256v1:secp384r1
HAProxy (with OpenSSL 3.5 or later)
global
ssl-default-bind-curves X25519MLKEM768:X25519:P-256:P-384
Caddy and Go
Go 1.24 and later offer X25519MLKEM768 by default when tls.Config.CurvePreferences is left empty, so current Caddy builds need no change. If you set curve preferences yourself, add it explicitly:
cfg := &tls.Config{
MinVersion: tls.VersionTLS12,
CurvePreferences: []tls.CurveID{tls.X25519MLKEM768, tls.X25519, tls.CurveP256},
}
Behind a CDN or load balancer
The visitor's connection ends at the edge, so the edge's settings are what this checker sees. Cloudflare documents X25519MLKEM768 for every proxied hostname. For other CDNs, cloud load balancers and WAFs, check the vendor's TLS policy options, then run this checker again. The connection from the edge to your origin is a separate hop with its own settings.
Why now
- Standards are final. NIST published ML-KEM (FIPS 203) and ML-DSA (FIPS 204) in August 2024.
- Deadlines exist. NIST IR 8547 proposes deprecating RSA and elliptic-curve key exchange and signatures after 2030 and disallowing them after 2035. The EU's coordinated roadmap asks member states to start inventories and migration by the end of 2026 and move high-risk systems by 2030.
- Clients are ready. Current Chrome, Edge, Firefox and Safari send X25519MLKEM768 by default, so enabling it on your server protects most visitors immediately.
- Recorded traffic is at risk. Harvest-now-decrypt-later means data with a long shelf life (health, finance, legal, personal data) needs post-quantum key exchange before a quantum computer arrives, not after.
Sources: NIST FIPS 203, NIST IR 8547 (draft), Cloudflare PQC docs, browser support table. Checked 29 September 2026.
Scan every domain you own, by API
Your public website is usually the easy part. APIs, login domains, mail web front-ends and customer portals often sit on older load balancers. The /v1/pqc-scan endpoint checks up to 20 hosts per request and returns the same JSON you see here, so you can build an inventory, watch it in CI, or alert when a host regresses.
curl https://siftwright.com/v1/pqc-scan \
-H "Authorization: Bearer sw_live_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"hosts": ["example.com", "api.example.com", "login.example.com"]}'
Every host that answers counts as one result on your plan (Starter includes 10,000 a month for $29). Hosts that don't answer are free. Read the docs.
Get an API keyNeed a scheduled inventory report? Ask for a data feed
Frequently asked questions
What does this checker test?
It opens real TLS connections to your server on port 443 and asks which key-exchange groups it accepts: the hybrid X25519MLKEM768 that browsers use by default, the NIST-curve hybrids, pure ML-KEM, the old Kyber draft and the classical curves. It also reads the certificate (over TLS 1.2, where it is sent unencrypted) and the HSTS header. Nothing beyond the handshake is sent, and no page content is stored.
What is X25519MLKEM768?
A hybrid key exchange that combines classical X25519 with ML-KEM-768, the lattice-based key encapsulation NIST standardised as FIPS 203 in August 2024. The session stays secure as long as either part holds, so it protects against a future quantum computer without trusting a new algorithm alone. Chrome, Edge, Firefox and Safari use it by default.
Why does it matter today if quantum computers can't break TLS yet?
Because of harvest now, decrypt later: anyone who records your encrypted traffic today can keep it and decrypt it once a large enough quantum computer exists. Post-quantum key exchange closes that gap for new sessions now. Signatures (certificates) matter less for recorded traffic, because forging a signature later doesn't unlock past sessions.
My certificate is RSA or ECDSA. Is that a problem?
Not yet, and it's the same for every public website: public certificate authorities don't issue ML-DSA certificates for the web today. Watch your CA's roadmap and keep certificate automation in place, because lifetimes are shrinking and the switch will be a certificate swap when it comes.
Why does it say a result is inferred from Cloudflare?
Our checker runs on Cloudflare Workers, which can't open raw TLS connections to Cloudflare's own addresses. For hosts that resolve to Cloudflare we report Cloudflare's documented edge support for X25519MLKEM768 instead of a live probe, and we label the result that way.
How do I turn on post-quantum key exchange?
Use a TLS library that supports ML-KEM (OpenSSL 3.5 or later, BoringSSL, Go 1.24 or later, or recent rustls) and put X25519MLKEM768 first in the groups list. On a CDN or load balancer, check the vendor's post-quantum settings. The guide below has config lines for nginx, Apache, HAProxy, Caddy and Go.
Can I scan many domains at once?
Yes. The /v1/pqc-scan API endpoint takes up to 20 hosts per call with any Siftwright API plan, and each host that answers counts as one result. The free checker here allows about 60 scans per day per network.
Is the checker free?
Yes, with no signup. Results are cached for 30 minutes per domain to keep it fast and polite to the servers we test.
Scan your whole estate, not just one domain
The same checks by API, 20 hosts per call, with every Siftwright plan. Plans from $29/month; hosts that don't answer are free.