How TLS works
Every TLS connection starts with a handshake, a short exchange that sets up encryption before any real data moves. In TLS 1.3, the current version, it takes one round trip.1
- Your device says hello. It lists the encryption methods it supports and sends its half of a key exchange.
- The server answers with its own half of the key exchange and its certificate, signed by a certificate authority your device already trusts.
- Your device checks the certificate to make sure it belongs to the name you asked for and hasn’t expired.
- Both sides work out the same session keys from the key exchange. The keys themselves never cross the network.
- Data flows encrypted, and each piece carries a check so tampering is detected.
TLS 1.3 uses fresh, temporary keys for every connection, which gives it forward secrecy: a server key stolen later doesn’t unlock traffic recorded earlier.1
TLS versions, and TLS vs SSL
SSL was the original protocol from the 1990s. TLS is its successor, and every version of SSL is long retired. People still say “SSL” and “SSL certificate” out of habit, but what runs today is TLS.
| Version | Year | Status |
|---|---|---|
| SSL 3.0 | 1996 | Must not be used2 |
| TLS 1.0 and 1.1 | 1999 and 2006 | Deprecated in 20213 |
| TLS 1.2 | 2008 | Still widely supported |
| TLS 1.3 | 2018 | Current. The specification was refreshed as RFC 9846 in July 20264 |
Why TLS matters
Without TLS, everything you send crosses Wi-Fi routers, internet providers and backbone networks as readable text. TLS is why a password typed into a website, or an email passed between providers, can’t simply be copied along the way.
What TLS doesn’t protect
TLS protects the connection between two machines, and its job ends when the data arrives. The server at the other end receives your data unencrypted and decides how to store it. An email can cross several TLS connections and still be readable by each provider that handles it. That is why TLS is called encryption in transit, and why stored data needs its own layer, such as zero-access or end-to-end encryption.
Where you’ll see TLS
- The web. HTTPS is HTTP carried inside TLS.
- Email. Mail servers turn TLS on with the STARTTLS command, and policies such as MTA-STS make it mandatory.
- Apps. Nearly every app on your phone talks to its servers over TLS.
TLS in Secria
In transit, Secria mail travels over TLS, and our domains publish an MTA-STS policy in enforce mode with TLS reporting. The Secria VPN app talks to our servers over hybrid post-quantum TLS. Protection doesn’t end with the connection: once a message arrives, your mailbox is stored with zero-access encryption.
Related terms
Sources
- IETF, RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (August 2018).
- IETF, RFC 7568: Deprecating Secure Sockets Layer Version 3.0 (June 2015).
- IETF, RFC 8996: Deprecating TLS 1.0 and TLS 1.1 (March 2021).
- IETF, RFC 9846: The Transport Layer Security (TLS) Protocol Version 1.3 (July 2026). Replaces RFC 8446.
Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.
Questions about TLS
What is the difference between TLS and SSL?
SSL is the older protocol and TLS is what replaced it. All versions of SSL are retired because of security flaws. When a product says SSL today, it almost always means TLS.
Is TLS the same as end-to-end encryption?
No. TLS encrypts data between your device and a server, and the server can read what arrives. End-to-end encryption keeps a message encrypted all the way to the recipient’s device, so the services in between only carry scrambled data.
Which version of TLS should be used?
TLS 1.3 where both sides support it, and TLS 1.2 otherwise. TLS 1.0 and 1.1 were formally deprecated by the IETF in 2021.
What is the difference between TLS and HTTPS?
HTTPS is the web’s HTTP protocol running inside a TLS connection. TLS is the general-purpose layer, and it also protects email, apps and many other kinds of traffic.