The domain sha3.si is for sale. Make an offer or buy it now →

Is your website quantum-safe?

Check whether a site accepts post-quantum key exchange (ML-KEM, the NIST FIPS 203 standard) and protects its traffic against harvest-now, decrypt-later attacks. Free, in seconds.

Try: cloudflare.com · google.com · github.com

Why this matters

Almost every HTTPS connection today agrees its keys with elliptic curves (X25519, P-256) or RSA. A large quantum computer running Shor's algorithm would break both. Nobody has one yet, but traffic can be recorded now and decrypted later, so data that must stay confidential for years is already at risk.

That is why NIST published the post-quantum standards ML-KEM (FIPS 203) and ML-DSA (FIPS 204) in 2024, and why governments have set migration timelines: NIST plans to deprecate today's public-key algorithms by 2030 and disallow them by 2035, and the UK and EU have published roadmaps aiming at 2030 to 2035 for critical systems.

What this check tests

TestHowWhy
Post-quantum key exchangeWe open a TLS 1.3 handshake offering only the hybrid group X25519MLKEM768. If the server completes it, it supports ML-KEM.This is the part that protects recorded traffic. 2 points.
TLS 1.3A normal handshake: which version does the server choose?Post-quantum key exchange exists only in TLS 1.3. 1 point.
CertificateKey type, signature, issuer, expiry and validity.Shown for information. Post-quantum certificates are not issued by public CAs yet.

X25519MLKEM768 combines classical X25519 with ML-KEM-768. An attacker would have to break both, so it is at least as strong as today's encryption, and safe against quantum computers. Chrome, Firefox, Safari and Edge already offer it.

Where SHA-3 comes in

ML-KEM is built on SHA-3: it uses SHA3-256, SHA3-512, SHAKE128 and SHAKE256 internally. Every post-quantum handshake this page detects runs SHA-3 under the hood.

Frequently asked

What does "quantum-safe" mean for a website?

That the key exchange protecting its HTTPS traffic uses post-quantum cryptography (ML-KEM, FIPS 203), usually as the hybrid X25519MLKEM768. Traffic recorded today then cannot be decrypted later by a quantum computer.

Why does it matter now if quantum computers cannot break encryption yet?

Because of harvest now, decrypt later: encrypted traffic can be recorded today and decrypted once a large quantum computer exists. Data that must stay secret for years needs post-quantum protection already.

Why is my certificate still classical?

Public certificate authorities do not issue post-quantum (ML-DSA) certificates yet. Key exchange is the part to fix first, because it protects recorded traffic; signatures only need to be quantum-safe once quantum computers exist.

Is the check safe for my server?

Yes. It opens two ordinary HTTPS handshakes on port 443, like a browser visiting your homepage, and sends no requests beyond that. Results are cached for ten minutes and the site you check is not stored.

How do I enable post-quantum key exchange?

Cloudflare enables it by default. Go 1.24+ servers and Caddy built with Go 1.24+ also do. With nginx or Apache, build against OpenSSL 3.5 or later and put X25519MLKEM768 first in the key-exchange groups.

Own sha3.si

A short, exact-match domain for one of the world's core cryptographic standards. Ideal for a security, cryptography, blockchain or developer-tools brand.

Buy now or make an offer Why this name