How to Check SSL Port 443 Availability and Response
Checking the SSL port 443 response allows you to verify that your secure web server is actively listening, properly completing the TLS handshake, and presenting a valid security certificate to clients. Whether you are troubleshooting an unexpected downtime or preparing for a new deployment, testing this port gives you immediate visibility into your server's transport layer health.
To diagnose issues quickly without installing command-line utilities, you can use the SSL Checker to instantly inspect your certificate chain, cipher support, and port 443 availability right from your browser.
Understanding SSL Port 443 and the TLS Handshake
Port 443 is the standard networking port designated for secure HTTPS traffic. When a client browser or API consumer connects to a server on this port, a cryptographic handshake takes place. This process negotiates encryption parameters, verifies the server's identity using an X.509 certificate, and establishes a secure tunnel before any HTTP application data is transmitted.
If any step in this sequence fails—such as a blocked firewall rule, an expired certificate, or an unsupported cipher suite—the connection drops, or the client displays a security warning. System administrators must look beyond simple TCP connectivity to verify that the application layer and TLS stack respond correctly.
How to Check TCP Connectivity to Port 443
Before investigating the TLS handshake, confirm that the underlying network path and operating system firewall permit traffic on TCP port 443 for your target host, such as example.com or the IP address 192.0.2.44.
Using Test-NetConnection (PowerShell)
Windows administrators can use the built-in PowerShell cmdlet to check if the remote host is accepting TCP connections on port 443.
Test-NetConnection -ComputerName example.com -Port 443
Sample Output:
ComputerName : example.com
RemoteAddress : 192.0.2.44
RemotePort : 443
InterfaceAlias : Ethernet
SourceAddress : 192.0.2.10
TcpTestSucceeded : True
A TcpTestSucceeded : True result confirms that the network routing, intermediate firewalls, and local operating system are allowing packets through to port 443.
Using Netcat (Linux and macOS)
On Unix-like systems, netcat (nc) provides a quick way to test TCP socket availability.
nc -zv example.com 443
Sample Output:
Connection to example.com 443 port [tcp/https] succeeded!
How to Check TLS Handshake and Certificate Response
Once you verify that TCP port 443 is open, you must inspect the SSL/TLS layer to ensure the server presents the correct certificate and responds with a successful cryptographic negotiation.
Using OpenSSL
The openssl s_client command is the industry standard for diagnosing SSL port 443 responses. It connects to the remote server, prints the certificate chain, displays negotiated cipher details, and allows you to interact with the TLS session.
openssl s_client -connect example.com:443 -servername example.com
Sample Output:
CONNECTED(00000003)
depth=2 C = US, O = Example Root CA, CN = Root CA G2
verify return:1
depth=1 C = US, O = Example Intermediate, CN = Issuing CA
verify return:1
depth=0 CN = example.com
verify return:1
---
Certificate chain
0 s:CN = example.com
i:C = US, O = Example Intermediate, CN = Issuing CA
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 256 bit
Secure Renegotiation IS NOT SUPPORTED
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not supported
---
Examine this output for key indicators:
- Verify return code:
verify return:1means the certificate chain is trusted by your local trust store. - Protocol version: Look for
TLSv1.2orTLSv1.3to ensure modern security standards are active. - Subject Name (CN): Confirm it matches the domain name you are trying to reach.
Using cURL
You can verify the HTTP response over port 443 while simultaneously checking SSL validity using curl.
curl -Iv https://example.com
Sample Output:
* Trying 192.0.2.44:443...
* Connected to example.com (192.0.2.44) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* Cipher selection: ALL:!EXPORT:!LOW:!aNULL:!eNULL:!SSLv2
* successfully set certificate verify locations:
* CAfile: /etc/ssl/cert.pem
* CApath: none
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* SSL certificate verify ok.
< HTTP/2 200
< content-type: text/html; charset=UTF-8
< server: nginx
Comparing SSL Testing Methods
| Method | Scope | Best Used For | Platform Support |
|---|---|---|---|
| PowerShell (Test-NetConnection) | Layer 4 (TCP) | Basic network reachability checks | Windows |
Netcat (nc) |
Layer 4 (TCP) | Quick socket port scanning | Linux, macOS |
OpenSSL (s_client) |
Layer 7 (TLS) | Detailed handshake, cipher, and cert analysis | Cross-Platform |
| cURL | Layer 7 (HTTPS) | Verifying full TLS and HTTP/2 response codes | Cross-Platform |
Common Mistakes and How to Fix Them
When troubleshooting SSL port 443 responses, administrators frequently run into a few common pitfalls:
- SNI (Server Name Indication) Missing: If your server hosts multiple SSL certificates on a single IP address, running
openssl s_clientwithout the-servernameflag will cause the web server to return a default or fallback certificate. Always include the hostname parameter. - Firewall and Security Group Misconfigurations: Cloud providers and on-premise firewalls often block inbound traffic on port 443. Check your provider's network settings (names may differ slightly such as Security Groups, Network ACLs, or Firewall Rules) to ensure TCP 443 is open to
0.0.0.0/0or your specific client subnet. - Expired or Untrusted Intermediate Certificates: If
opensslreturnsverify return:1on your local machine but external clients report errors, your web server is likely failing to serve the required intermediate certificate chain. - Outdated Cipher Suites: Forcing deprecated protocols like SSLv3 or TLSv1.0 can cause modern client applications to abort the handshake entirely. Update your web server configuration (such as Nginx or Apache configuration files) to enforce TLS 1.2 and TLS 1.3 exclusively.
SSL Port 443 Diagnostic Checklist
- Confirm DNS records (A and AAAA) correctly resolve to your server's public IP address.
- Verify local and cloud firewall rules allow inbound TCP traffic on port 443.
- Test TCP connectivity using PowerShell or netcat to ensure the socket is listening.
- Run an OpenSSL handshake test to verify certificate chain validity and expiration dates.
- Send an HTTPS request via cURL or browser to confirm a
200 OKor expected HTTP status code response.