SSL Toolkit Logo

Cloudflare SSL Checker

Check Cloudflare SSL configuration

About Cloudflare SSL Checker

The Cloudflare SSL Checker verifies whether a domain is behind Cloudflare and analyzes its SSL/TLS configuration. It detects the encryption mode (Flexible, Full, or Full Strict), checks edge certificate status, identifies TLS version support, and inspects Cloudflare-specific HTTP headers like CF-Ray and Server headers.

Use Cases

  • Verify your Cloudflare SSL/TLS encryption mode is set correctly
  • Confirm Cloudflare proxy is active for your domain
  • Troubleshoot SSL misconfigurations behind Cloudflare
  • Audit edge certificate issuer and nameserver configuration

How to Use

  • Enter the domain name you want to check (e.g., example.com)
  • Click "Run" to start the Cloudflare SSL analysis
  • Review the results including Cloudflare status, certificate issuer, and detected HTTP headers

Frequently Asked Questions

The checker identifies whether your domain uses Cloudflare Flexbile, Full, or Full Strict SSL mode based on the edge certificate and origin server handshake. It analyzes the CF-Ray header, Server header, and certificate chain to determine the encryption mode.
Cloudflare acts as a reverse proxy, terminating SSL at the edge and optionally re-encrypting traffic to your origin server. Flexible mode encrypts browser-to-Cloudflare only. Full mode encrypts both legs but allows any origin certificate. Full Strict requires a valid origin certificate.
If your domain does not show as behind Cloudflare, the DNS may not be proxied through Cloudflare, or the Cloudflare proxy may be temporarily disabled. Check that your nameservers point to Cloudflare and that the orange cloud icon is enabled in your Cloudflare dashboard.

Tips & Best Practices

  • Choose the right Cloudflare SSL mode for your security requirements
  • Verify Cloudflare SSL configuration matches your origin server setup
  • Use Cloudflare Origin Certificate for secure origin connections
  • Monitor Cloudflare SSL status for certificate expiry and issues

Technical Details

Modes: Off, Flexible, Full, Full (Strict), Strict (SPA)
Certificates: Universal SSL, dedicated certificates, Origin certificates
Edge: Cloudflare edge SSL termination and origin connections
Output: Cloudflare SSL configuration analysis and recommendations