Test your connection.

Check what gets through. Keep the evidence.

Browser checks use supported HTTPS endpoints.

Quick check unavailable: receiver is not configured.

Connection journey

Not run
  1. DNS
  2. TCP
  3. TLS
  4. HTTP
Measured connection evidence
CheckResultTime
DNS resolutionNot run—
TCP connectionNot run—
TLS handshakeNot run—
HTTP responseNot run—

Run a check to see measured results.

Reports stay on this device unless you choose to share them.

Advanced: select a report interpretation runtime

Known report versions use a reviewed bundled interpretation context. For a custom runtime ID, explicitly select its matching JSON here before importing the report. This local context interprets claims; it does not authenticate a producer, authorize a test, fetch anything or change public service status. Earlier reports keep their original context.

  • Known v0.1 context remains available. v0.2 interpretation loads on demand.

At most four custom runtimes, 1 MiB each, are held in this page's memory. No imported context can replace a known identity with different content.

Import or run two validated reports to compare.A validated report is required before export.

Get native command

Commands are prepared locally. Copying a command does not run a test.

Command unavailable: receiver is not configured.

Need a deeper look?

Use the Rust client for raw TCP, private destinations and detailed evidence.

Connection details
Connection details

Keep the evidence in context.

Browser HTTPS checks use the browser's trust and security policy. A generic fetch error cannot identify DNS, TCP, TLS or firewall failure. Native reports retain their own producer, network context and observation time.

The Rust client is in development. A verified signed download is not available yet. Prepared plans use approved Layer8 targets; authorized private destinations stay in the native client.

Full port range is a native capability. Presets are bounded and a single selected port is the default. No subnet discovery or automatic scan runs from this page.

About these checks

Website, public DNS, certificates, PKI publication and OCSP status come from independent monitoring. Device checks and imported reports cannot change these five public status rows. Missing or stale evidence remains unknown or stale.

PKI publication needs fresh expected source and checkpoint metadata, served artifact agreement and an independent consumer check. A valid fetched artifact alone cannot establish the publication pipeline's health.

Privacy

Files you import are parsed and rendered on this device. This page never uploads reports. A quick check sends a fresh nonce to the configured receiver; that receiver can observe the source address of the request. Exported files are saved only when you choose an export action.

Help

Select a mode, port and address family. Browser execution requires a supported configured HTTPS endpoint. Native mode prepares instructions or a validated plan. Import a local JSON report to review evidence, compare two runs and prepare a redacted export.