See the connection and response #
See the connection and response
Network tools · Local shell; platform and privileges as described below
Replace these example values: example.com.
curl -v --connect-timeout 5 --max-time 15 -o /dev/null https://example.com/Replace these example values: example.com.
curl -sS -D - -o /dev/null --max-time 15 https://example.com/Verbose output explains connection setup; response headers show the HTTP result. Headers and diagnostics may contain sensitive cookies or authorization details, so review them before sharing. The first timeout limits connection setup, while the overall time limit bounds the entire operation.
Test a backend without changing DNS #
Test a backend without changing DNS
Network tools · Local shell; platform and privileges as described below
Replace these example values: example.com, 192.0.2.20.
curl --resolve example.com:443:192.0.2.20 \
--connect-timeout 5 --max-time 15 -v -o /dev/null https://example.com/The URL still supplies the hostname for HTTPS identity checks and the HTTP request. Only the address selection is overridden for that host and port. This is preferable to requesting https://192.0.2.20/, which changes the identity being tested. A redirect to another hostname or port is a separate destination and may require its own mapping. This example assumes a direct connection. Check verbose output for an environment-configured proxy; --resolve does not disable proxy use. Where direct access is permitted, add --noproxy example.com for this host-specific backend test.
Record timings #
Record timings
Network tools · Local shell; platform and privileges as described below
Replace these example values: example.com.
curl -sS -o /dev/null --max-time 15 \
-w 'code=%{http_code} ip=%{remote_ip} dns=%{time_namelookup} connect=%{time_connect} tls=%{time_appconnect} first_byte=%{time_starttransfer} total=%{time_total}\n' \
https://example.com/For a simple new HTTPS connection, the timing milestones are cumulative from the start. Do not add them together. The difference between connection and TLS milestones helps isolate handshake time, while time to first byte includes work before the response begins. Redirects, proxies and connection reuse complicate direct comparisons; keep the test setup constant.
Read failures at the right layer #
Name-resolution errors point toward DNS. Connection failure or timeout requires a path and listener check. Certificate errors require trust, hostname and date checks. HTTP 401, 403 or 500 means an HTTP-speaking system responded, so it is a different finding from an unreachable TCP port.
Avoid -k as the default troubleshooting recipe: it disables an important part of the test. Also remember that -I sends HEAD, not GET; applications may handle them differently. Reproduce the user's actual method and path when the basic connection works but the application still fails.
Sources
Documentation reviewed: 8 October 2026