William OGOU Cybersecurity Blog

Published

- 4 min read

Is My Website Quantum-Safe? How to Check PQC in 5 Minutes

img of Is My Website Quantum-Safe? How to Check PQC in 5 Minutes

Is your website PQC safe? If your domain negotiates TLS 1.3 with the key exchange group X25519MLKEM768, your visitor traffic is protected against harvest-now, decrypt-later attacks. If it negotiates X25519, P-256, or anything older, a quantum computer could one day decrypt everything an adversary records today.

The good news: checking takes about five minutes, and on September 29, 2026 Cloudflare made it even easier by exposing per-domain post-quantum telemetry in HTTP Traffic Analytics, Logpush, and Log Explorer. Here are three ways to check any domain yours or anyone else’s and what to do about the result.

What to Remember

  • The one value that matters: X25519MLKEM768 in TLS 1.3 means post-quantum key exchange. Anything else (X25519, P-256, P-384, RSA) means quantum-vulnerable.
  • Check : Browser (any site, 30 seconds): Chrome DevTools → Security tab shows the key exchange group of your current connection.
  • Not compliant? Enable TLS 1.3, upgrade the origin’s TLS stack to support X25519MLKEM768.

Check : Your Browser (30 Seconds, Any Website)

Browser Security Tab

In Chrome, right-click → Inspect → Security tab. It shows the TLS version and key exchange group for the live connection. Seeing TLS 1.3 with X25519MLKEM768 means that specific connection is quantum-safe. Seeing X25519 or P-256 means it is not though note this reflects one connection, not the whole domain.

This is the fastest answer to “is this website PQC safe right now,” but a single sample can mislead: different visitors negotiate different groups depending on their client support.

Conclusion

“Is my domain PQC compliant” now has a measurable answer: the percentage of connections negotiating X25519MLKEM768 on both the visitor and origin sides. Check it in the browser in seconds, prove it in Analytics and logs for auditors, and close the gap with TLS 1.3, origin upgrades, or Tunnel. With NIST deprecating RSA and ECC by 2030 and harvest-now, decrypt-later collection happening today, that percentage belongs on your security dashboard next to patch coverage.

To further enhance your cloud security and PQC readiness, contact me on LinkedIn Profile or [email protected].

Frequently Asked Questions (FAQ)

How do I check if my website is PQC safe?

The fastest check is Chrome DevTools: Inspect, Security tab, and look for TLS 1.3 with X25519MLKEM768. For the full picture on Cloudflare domains, use Analytics, HTTP Traffic, TLS Key Exchange card for per-domain post-quantum share, plus ClientTLSKeyExchangeGroup in logs for per-request evidence.

What does it mean for a domain to be PQC compliant?

It means connections negotiate post-quantum key exchange in TLS 1.3, the group X25519MLKEM768 instead of quantum-vulnerable X25519, P-256, P-384, or RSA. Full compliance covers both the visitor-to-edge and the edge-to-origin connections, since either side can leak harvestable traffic.

Why is my domain still using classical X25519 with TLS 1.3 on?

Most often the clients are non-browser agents without X25519MLKEM768 support, or the origin forces classical crypto through outdated TLS configuration. Check the non-PQC traffic filter in Analytics, verify origin support with Automatic Key Exchange or Radar, and consider Cloudflare Tunnel for legacy origins.

Does post-quantum key exchange also fix authentication?

No. X25519MLKEM768 protects session confidentiality against future decryption, but certificates and signatures still need post-quantum authentication (ML-DSA, Merkle Tree Certificates). See the companion piece on post-quantum authentication to origins for that half of the migration.

When do I need to be PQC ready?

NIST has stated RSA and ECC should be deprecated by 2030, and harvest-now, decrypt-later means long-lived data (finance, healthcare, public sector, telecom) needs protection now. Cloudflare targets full post-quantum security by 2029.

Resources


William OGOU

William OGOU

Need help implementing Zero Trust strategy or securing your cloud infrastructure? I help organizations build resilient, compliance-ready security architectures.