XiaTools

How to Check SSL Port 443 Availability and Response

Updated 11 Oct 2026

Checking the SSL port 443 response allows you to verify that your secure web server is actively listening, properly completing the TLS handshake, and presenting a valid security certificate to clients. Whether you are troubleshooting an unexpected downtime or preparing for a new deployment, testing this port gives you immediate visibility into your server's transport layer health.

To diagnose issues quickly without installing command-line utilities, you can use the SSL Checker to instantly inspect your certificate chain, cipher support, and port 443 availability right from your browser.

Understanding SSL Port 443 and the TLS Handshake

Port 443 is the standard networking port designated for secure HTTPS traffic. When a client browser or API consumer connects to a server on this port, a cryptographic handshake takes place. This process negotiates encryption parameters, verifies the server's identity using an X.509 certificate, and establishes a secure tunnel before any HTTP application data is transmitted.

If any step in this sequence fails—such as a blocked firewall rule, an expired certificate, or an unsupported cipher suite—the connection drops, or the client displays a security warning. System administrators must look beyond simple TCP connectivity to verify that the application layer and TLS stack respond correctly.

How to Check TCP Connectivity to Port 443

Before investigating the TLS handshake, confirm that the underlying network path and operating system firewall permit traffic on TCP port 443 for your target host, such as example.com or the IP address 192.0.2.44.

Using Test-NetConnection (PowerShell)

Windows administrators can use the built-in PowerShell cmdlet to check if the remote host is accepting TCP connections on port 443.

Test-NetConnection -ComputerName example.com -Port 443

Sample Output:

ComputerName     : example.com
RemoteAddress    : 192.0.2.44
RemotePort       : 443
InterfaceAlias   : Ethernet
SourceAddress    : 192.0.2.10
TcpTestSucceeded : True

A TcpTestSucceeded : True result confirms that the network routing, intermediate firewalls, and local operating system are allowing packets through to port 443.

Using Netcat (Linux and macOS)

On Unix-like systems, netcat (nc) provides a quick way to test TCP socket availability.

nc -zv example.com 443

Sample Output:

Connection to example.com 443 port [tcp/https] succeeded!

How to Check TLS Handshake and Certificate Response

Once you verify that TCP port 443 is open, you must inspect the SSL/TLS layer to ensure the server presents the correct certificate and responds with a successful cryptographic negotiation.

Using OpenSSL

The openssl s_client command is the industry standard for diagnosing SSL port 443 responses. It connects to the remote server, prints the certificate chain, displays negotiated cipher details, and allows you to interact with the TLS session.

openssl s_client -connect example.com:443 -servername example.com

Sample Output:

CONNECTED(00000003)
depth=2 C = US, O = Example Root CA, CN = Root CA G2
verify return:1
depth=1 C = US, O = Example Intermediate, CN = Issuing CA
verify return:1
depth=0 CN = example.com
verify return:1
---
Certificate chain
 0 s:CN = example.com
   i:C = US, O = Example Intermediate, CN = Issuing CA
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 256 bit
Secure Renegotiation IS NOT SUPPORTED
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not supported
---

Examine this output for key indicators:

  • Verify return code: verify return:1 means the certificate chain is trusted by your local trust store.
  • Protocol version: Look for TLSv1.2 or TLSv1.3 to ensure modern security standards are active.
  • Subject Name (CN): Confirm it matches the domain name you are trying to reach.

Using cURL

You can verify the HTTP response over port 443 while simultaneously checking SSL validity using curl.

curl -Iv https://example.com

Sample Output:

*   Trying 192.0.2.44:443...
* Connected to example.com (192.0.2.44) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* Cipher selection: ALL:!EXPORT:!LOW:!aNULL:!eNULL:!SSLv2
* successfully set certificate verify locations:
*  CAfile: /etc/ssl/cert.pem
*  CApath: none
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* SSL certificate verify ok.
< HTTP/2 200 
< content-type: text/html; charset=UTF-8
< server: nginx

Comparing SSL Testing Methods

Method Scope Best Used For Platform Support
PowerShell (Test-NetConnection) Layer 4 (TCP) Basic network reachability checks Windows
Netcat (nc) Layer 4 (TCP) Quick socket port scanning Linux, macOS
OpenSSL (s_client) Layer 7 (TLS) Detailed handshake, cipher, and cert analysis Cross-Platform
cURL Layer 7 (HTTPS) Verifying full TLS and HTTP/2 response codes Cross-Platform

Common Mistakes and How to Fix Them

When troubleshooting SSL port 443 responses, administrators frequently run into a few common pitfalls:

  1. SNI (Server Name Indication) Missing: If your server hosts multiple SSL certificates on a single IP address, running openssl s_client without the -servername flag will cause the web server to return a default or fallback certificate. Always include the hostname parameter.
  2. Firewall and Security Group Misconfigurations: Cloud providers and on-premise firewalls often block inbound traffic on port 443. Check your provider's network settings (names may differ slightly such as Security Groups, Network ACLs, or Firewall Rules) to ensure TCP 443 is open to 0.0.0.0/0 or your specific client subnet.
  3. Expired or Untrusted Intermediate Certificates: If openssl returns verify return:1 on your local machine but external clients report errors, your web server is likely failing to serve the required intermediate certificate chain.
  4. Outdated Cipher Suites: Forcing deprecated protocols like SSLv3 or TLSv1.0 can cause modern client applications to abort the handshake entirely. Update your web server configuration (such as Nginx or Apache configuration files) to enforce TLS 1.2 and TLS 1.3 exclusively.

SSL Port 443 Diagnostic Checklist

  • Confirm DNS records (A and AAAA) correctly resolve to your server's public IP address.
  • Verify local and cloud firewall rules allow inbound TCP traffic on port 443.
  • Test TCP connectivity using PowerShell or netcat to ensure the socket is listening.
  • Run an OpenSSL handshake test to verify certificate chain validity and expiration dates.
  • Send an HTTPS request via cURL or browser to confirm a 200 OK or expected HTTP status code response.

Frequently asked questions

Why does my browser show an SSL error even though port 443 is open?

An open port simply means the server is listening for network traffic. SSL errors occur at the application layer when the certificate is expired, self-signed, untrusted by the client, or configured with an incorrect domain name match.

How can I check SSL port 443 response behind a load balancer?

When testing behind a load balancer or reverse proxy, the load balancer terminates the SSL connection. Your test will verify the load balancer's certificate configuration rather than the backend application server, unless you use end-to-end encryption settings.

What does a 'Handshake Failure' error mean in OpenSSL?

A handshake failure indicates that the client and server could not agree on encryption parameters. This is typically caused by mismatched TLS protocol versions or a complete lack of overlapping supported cipher suites.

Can I check SSL port 443 response for IPv6 addresses?

Yes, both OpenSSL and cURL support IPv6. For OpenSSL, you simply provide the bracketed IPv6 address or valid hostname, ensuring your local network routing has functional IPv6 connectivity to the target host.

How do I test if my web server supports TLS 1.3?

You can force OpenSSL to negotiate using TLS 1.3 specifically by running the command with the `-tls1_3` flag. If the server supports it, the handshake will succeed and display the TLS 1.3 protocol line in the output.

Related articles

Free tools