SSL Handshake Tracer - Trace TLS Handshake Step by Step

This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.

About SSL Handshake Tracer

The CSR.plus SSL Handshake Tracer performs a real TLS handshake against any host and port, recording every step of the connection. It reveals DNS resolution, TCP connectivity, the negotiated TLS version and cipher suite, and each certificate returned — ideal for debugging mysterious TLS failures.

While an SSL checker reports the final certificate, a tracer shows you the whole journey. When a connection fails with a cryptic error, handshake tracing pinpoints exactly where it breaks: DNS, TCP, TLS version negotiation, or certificate validation. This online tracer replaces openssl s_client -trace debugging sessions for day-to-day troubleshooting.

Why use

  • Step-by-step log of DNS, TCP, and TLS handshake phases
  • See the negotiated TLS version and cipher suite at a glance
  • Inspect every certificate returned during the handshake
  • Trace any host and port, including mail, LDAP, and custom services

How to use

  1. Enter the host and port you want to trace (for example example.com:443).
  2. The tracer walks through DNS, TCP, and the TLS handshake, logging each stage.
  3. Inspect the log to find the exact step where the connection fails or degrades.
  4. Review the negotiated protocol, cipher, and presented certificate chain.

Frequently asked questions

▸What does the tracer actually do?

It opens a live TLS connection and reports DNS, TCP, handshake results, and the certificate chain, step by step.

▸Can it trace non-443 ports?

Yes. Specify any port to troubleshoot services such as mail, LDAP, or custom HTTPS endpoints.

▸Why might a handshake show a weak protocol?

If the server negotiates outdated TLS 1.0/1.1 or weak ciphers, the tracer flags it so you can harden the configuration.

▸When should I use a tracer instead of a checker?

Use it when a connection fails or behaves oddly. A checker only shows the final certificate; a tracer exposes the exact failing step.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate Viewer

Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.