SSL Handshake Tracer - Trace TLS Handshake Step by Step
This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.
About SSL Handshake Tracer
The CSR.plus SSL Handshake Tracer performs a real TLS handshake against any host and port, recording every step of the connection. It reveals DNS resolution, TCP connectivity, the negotiated TLS version and cipher suite, and each certificate returned — ideal for debugging mysterious TLS failures.
While an SSL checker reports the final certificate, a tracer shows you the whole journey. When a connection fails with a cryptic error, handshake tracing pinpoints exactly where it breaks: DNS, TCP, TLS version negotiation, or certificate validation. This online tracer replaces openssl s_client -trace debugging sessions for day-to-day troubleshooting.
Why use
- Step-by-step log of DNS, TCP, and TLS handshake phases
- See the negotiated TLS version and cipher suite at a glance
- Inspect every certificate returned during the handshake
- Trace any host and port, including mail, LDAP, and custom services
How to use
- Enter the host and port you want to trace (for example example.com:443).
- The tracer walks through DNS, TCP, and the TLS handshake, logging each stage.
- Inspect the log to find the exact step where the connection fails or degrades.
- Review the negotiated protocol, cipher, and presented certificate chain.
Frequently asked questions
▸What does the tracer actually do?
It opens a live TLS connection and reports DNS, TCP, handshake results, and the certificate chain, step by step.
▸Can it trace non-443 ports?
Yes. Specify any port to troubleshoot services such as mail, LDAP, or custom HTTPS endpoints.
▸Why might a handshake show a weak protocol?
If the server negotiates outdated TLS 1.0/1.1 or weak ciphers, the tracer flags it so you can harden the configuration.
▸When should I use a tracer instead of a checker?
Use it when a connection fails or behaves oddly. A checker only shows the final certificate; a tracer exposes the exact failing step.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
Certificate / Key Matcher
Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.
PEM Viewer
Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.
SSL Format Converter
Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
Let's Encrypt Checker
Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
CAA Record Checker
Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.
Certificate Revocation Checker
Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.