Why quantum computers
break today’s encryption
Almost all encryption on the internet relies on math that quantum computers will be able to undo. This page explains the threat in plain language — and shows exactly what PQScore checks when it scores your domain.
An adversary doesn’t need a quantum computer today to threaten you today. They can record your encrypted traffic now — customer data, financial transactions, internal communications — and simply store it.
When a sufficiently powerful quantum computer arrives (estimated around 2030), that stored traffic gets decrypted retroactively. Anything with a long shelf life — health records, trade secrets, state data — is already at risk the moment it’s sent.
A threat with deadlines
Q-Day — the point where quantum computers can break RSA and elliptic-curve cryptography — is estimated between 2028 and 2035. Regulators aren’t waiting: migration mandates are already on the calendar.
What we test
Every scan runs 11 checks against your domain — across TLS, DNS and email. Each check carries a weight that reflects how much it matters for quantum resistance. Together they sum to 100, your PQScore.
Key Exchange
30 ptsCertificate Signature
25 ptsDNSSEC
15 ptsCertificate Hygiene
8 ptsEmail Encryption (STARTTLS)
4 ptsLegacy TLS Protocols
4 ptsWeak Cipher Suites
3 ptsHTTP Strict Transport Security
3 ptsDKIM Email Signing
4 ptsDMARC Policy
2 ptsSPF Record
2 ptsWe also gather SSH and API-endpoint signals for the detailed report, but those don’t affect the numeric score — only the 11 weighted checks above do.
From 100 down
Every domain starts at 100. Each weakness subtracts a share of its check’s weight — a fully quantum-vulnerable key exchange costs the most, a missing SPF record the least. The result lands in one of four risk bands.
See where your domain stands
Run a free scan and get your PQScore, a sector benchmark, and a prioritised migration roadmap — in about a minute.