Evidence before a verdict.
CheckPQC helps people understand post-quantum cryptography across websites, applications and services. The site provides local reference scripts and technology guides; checkpqc.app checks its own browser connection and offers free public-domain TLS scans.
What we measure
The banner on checkpqc.com tests your browser's connection to checkpqc.app and labels that destination. It does not measure the connection to checkpqc.com's hosting provider.
The browser check reports the negotiated TLS group observed by CheckPQC's TLS terminator for the check request. If a proxy terminates TLS, the observation may describe that proxy's upstream connection. Missing or unrecognized data stays unknown.
The local TLS script makes two certificate-verified TLS 1.3 connections: local defaults and an X25519MLKEM768-only offer. It reports each observed result separately. Failure is inconclusive; a classical result does not prove that an endpoint lacks every PQC algorithm.
Website domain scans connect from our server to a public DNS hostname on TCP 443. Results describe that vantage point and may differ from your local connection. Rate limits and target restrictions apply.
What a result does not establish
- Whether every app on the device uses PQC.
- End-to-end messaging encryption, backups or encryption at rest.
- PQC signatures in certificates or software updates.
- Connections beyond a CDN, proxy, load balancer or mail relay.
- A compliance certification or a prediction of future cryptanalysis.
Why post-quantum key exchange matters
Traffic collected today could be at risk from future quantum attacks on classical public-key cryptography. Hybrid exchanges combine classical and post-quantum mechanisms. Key exchange and digital signatures are separate migration tasks.
Read the standards: NIST ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). For the tools used here, see OpenSSL's group documentation and OpenSSH's PQ guidance.
How CheckPQC is changing
The standalone public API product and packaged CLI are being phased out. Free website scans continue through the website backend. Reference scripts run on your machine and do not send targets or results to CheckPQC. Existing users can read the migration notice. The API service supports the website; it is not a separately supported public API product.
Technology guides link to primary sources. Software support changes; record your version, configuration, date and observed evidence rather than treating a version number as proof.