
Is your website PQC safe? If your domain negotiates TLS 1.3 with the key exchange group X25519MLKEM768, your visitor traffic is protected against harvest-now, decrypt-later attacks. If it negotiates X25519, P-256, or anything older, a quantum computer could one day decrypt everything an adversary records today.
The good news: checking takes about five minutes, and on September 29, 2026 Cloudflare made it even easier by exposing per-domain post-quantum telemetry in HTTP Traffic Analytics, Logpush, and Log Explorer. Here are three ways to check any domain yours or anyone else’s and what to do about the result.
What to Remember
- The one value that matters:
X25519MLKEM768in TLS 1.3 means post-quantum key exchange. Anything else (X25519, P-256, P-384, RSA) means quantum-vulnerable. - Check : Browser (any site, 30 seconds): Chrome DevTools → Security tab shows the key exchange group of your current connection.
- Not compliant? Enable TLS 1.3, upgrade the origin’s TLS stack to support X25519MLKEM768.
Check : Your Browser (30 Seconds, Any Website)

In Chrome, right-click → Inspect → Security tab. It shows the TLS version and key exchange group for the live connection. Seeing TLS 1.3 with X25519MLKEM768 means that specific connection is quantum-safe. Seeing X25519 or P-256 means it is not though note this reflects one connection, not the whole domain.
This is the fastest answer to “is this website PQC safe right now,” but a single sample can mislead: different visitors negotiate different groups depending on their client support.
Conclusion
“Is my domain PQC compliant” now has a measurable answer: the percentage of connections negotiating X25519MLKEM768 on both the visitor and origin sides. Check it in the browser in seconds, prove it in Analytics and logs for auditors, and close the gap with TLS 1.3, origin upgrades, or Tunnel. With NIST deprecating RSA and ECC by 2030 and harvest-now, decrypt-later collection happening today, that percentage belongs on your security dashboard next to patch coverage.
To further enhance your cloud security and PQC readiness, contact me on LinkedIn Profile or [email protected].
Frequently Asked Questions (FAQ)
How do I check if my website is PQC safe?
The fastest check is Chrome DevTools: Inspect, Security tab, and look for TLS 1.3 with X25519MLKEM768. For the full picture on Cloudflare domains, use Analytics, HTTP Traffic, TLS Key Exchange card for per-domain post-quantum share, plus ClientTLSKeyExchangeGroup in logs for per-request evidence.
What does it mean for a domain to be PQC compliant?
It means connections negotiate post-quantum key exchange in TLS 1.3, the group X25519MLKEM768 instead of quantum-vulnerable X25519, P-256, P-384, or RSA. Full compliance covers both the visitor-to-edge and the edge-to-origin connections, since either side can leak harvestable traffic.
Why is my domain still using classical X25519 with TLS 1.3 on?
Most often the clients are non-browser agents without X25519MLKEM768 support, or the origin forces classical crypto through outdated TLS configuration. Check the non-PQC traffic filter in Analytics, verify origin support with Automatic Key Exchange or Radar, and consider Cloudflare Tunnel for legacy origins.
Does post-quantum key exchange also fix authentication?
No. X25519MLKEM768 protects session confidentiality against future decryption, but certificates and signatures still need post-quantum authentication (ML-DSA, Merkle Tree Certificates). See the companion piece on post-quantum authentication to origins for that half of the migration.
When do I need to be PQC ready?
NIST has stated RSA and ECC should be deprecated by 2030, and harvest-now, decrypt-later means long-lived data (finance, healthcare, public sector, telecom) needs protection now. Cloudflare targets full post-quantum security by 2029.
Resources
- Cloudflare announcement: Is your domain using post-quantum encryption? (September 29, 2026, by Andrew Depke, Sophie Park, and Sharon Goldberg)
- Origin key agreement: Cloudflare Post-Quantum TLS: Automatic Key Exchange Explained
- Origin authentication: Post-quantum authentication to origins is now supported
- Migration planning: The Definitive Post-Quantum Cryptography Migration Checklist