SSL/TLS Learning Center
Practical, engineer-grade guides to TLS, certificates, email authentication and HTTP security headers. Every article leads with the direct answer, then goes deep enough to actually ship the change — and links to the free tool that checks your work.
- Public TLS certificates have been capped at 200 days since 15 March 2026 — next step 100 days on 15 March 2027, then 47 days in 2029, with domain-validation reuse falling to just 10 days. The 47-day survival guide →
- Let's Encrypt's default certificate drops to 64 days on 10 Feb 2027
and 45 days in 2028; its 6-day
shortlivedprofile and IP-address certs went GA on 15 January 2026. Certificate types → - Let's Encrypt stopped issuing client-auth certificates on 8 July 2026. If you used one for mTLS, it is already broken. What to do →
- Post-quantum key exchange now protects over two-thirds of browser traffic to Cloudflare, and US Executive Order 14412 (22 June 2026) set federal deadlines of 2030/2031. Post-quantum TLS →
Start here
New to this, or inherited someone else's certificates? Read in this order: SSL/TLS basics → which certificate you need → how to configure it properly → how to automate renewal before lifetimes shrink. Or just scan your domain and read whatever it complains about.
SSL / TLS basics
How browsers and servers actually agree to encrypt traffic — handshake, certificates, sessions — without the math degree.
Read articleCommon vulnerabilities
POODLE, Heartbleed, BEAST, CRIME, ROBOT — what each one was, what to look for, and why they're (mostly) extinct.
Read articleWhy monitoring matters
One expired cert ruins a Friday. A short story about regressions you didn't ship and how to catch them anyway.
Read articleSSL best practices
Our opinionated, no-bullshit checklist for getting and staying at A+ — modern ciphers, HSTS, OCSP, CT, the works.
Read articleCertificate types explained
DV, OV, EV and wildcard — the differences, when each is worth paying for, and the surprising answer for most teams (spoiler: DV).
Read article2026 trends
Post-quantum TLS
ML-KEM hybrid key exchange now ships by default in Chrome, Firefox and Safari. What's live, what's coming for certificates, and how to test your servers.
Read articleACME, ARI & 47-day certs
Public TLS lifetimes drop to 47 days in 2029. ACME automation, RFC 9773 Renewal Info, and the monitoring you still need on top.
Read articleTop 10 misconfigurations
The ten patterns we keep seeing in 2026 — incomplete chains, weak HSTS, RSA-KEX, wildcard sprawl — what they cost and how to fix each.
Read articleAI agents & bot auth
Web Bot Auth and HTTP Message Signatures (RFC 9421) finally let you cryptographically verify which AI scrapers are crawling you. The TLS angle underneath.
Read articleEmail security
Email security basics
SPF, DKIM and DMARC — what they each do, why you need all three, and how to roll them out without breaking sending.
Read articleAuthentication guide
MTA-STS, DANE, BIMI and TLS-RPT — the second wave of email auth, in plain English.
Read articleDeliverability guide
Reputation, inbox placement, what mailbox providers actually look at, and how to read your DMARC aggregate reports.
Read articleWeb security
State of Security Headers 2026 Original research
We graded the HTTP security headers of the Tranco top 5,000 sites. 59% score F, only 15.9% reach a good grade, and Big Tech is the worst-performing sector — google.com and microsoft.com both F. Full dataset and methodology inside.
Read the reportHTTP security headers
Strict-Transport-Security, Content-Security-Policy, Permissions-Policy and friends — what each header does, sensible defaults, and what'll break if you go too strict.
Read articleRead it, then check it
Every guide has a tool that verifies the thing it just taught you. All free, no signup.
| If you're reading about… | Check your own domain with |
|---|---|
| Best practices / Top 10 misconfigurations | Full SSL scan — grade, protocols, ciphers, chain |
| ACME & 47-day certs | Certificate lifecycle checker — where you sit against the SC-081 schedule |
| Post-quantum TLS | PQC readiness checker — does your server negotiate X25519MLKEM768? |
| CAA records | CAA checker — which CAs may issue for you |
| Certificate types | Certificate decoder · key matcher · CSR generator |
| Hardening a server | Config generator — nginx/Apache configs that score A+ |
| HTTP security headers | Compliance checker — headers vs. PCI DSS, NIST, HIPAA |