Some protocol versions could not be tested by this scanner
What this check looks for
We tested the versions we can speak and found what is shown here. ‹versions› could not be tested, so nothing on this page says whether the server accepts them.
Why it matters
An untested version is not a disabled one. A server that still accepts a version no modern client uses would be a serious finding — which is exactly why this page says the version was not checked rather than showing it as clear. The score is capped for what was not verified, and the gap is stated beside it; nothing here is a fact about your server.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- TLS
- Module
- Tls protocols
- Fix owned by
- third party
- In the ruleset since
- 2026.09
Technical detail
‹reason›
Every version from SSLv2 to TLS 1.3 is asked for on every scan: TLS 1.0–1.3 through OpenSSL, SSLv2 and SSLv3 with a hand-built ClientHello in each version's own framing (docs/26 §19.6). A version lands here when this run could not get an answer for it — the connection was refused or reset, the reply timed out, the server closed without answering, or the handshake budget ran out first. Another run may answer it. The rule for that version produces neither a pass nor a fail on this scan.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.