Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
CN=*.radarfirst.com
Issuer
C=US, O=Amazon, CN=Amazon RSA 2048 M01
Valid From
December 19, 2025
Valid Until
January 16, 2027
375 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D0:39:D5:00:49:F3:07:45:AE:00:CE:81:A1:95:1D:85:9B:51:43:E6:8A:B9:81:75:55:DB:85:A5:B6:B8:B8:18
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
base-uri; connect-src; frame-ancestors; +10 more
base-uri https://*.radarfirst.com;connect-src 'self' https://embedwistia-a.akamaihd.net https://*.litix.io https://*.wistia.com *.product-radar.radarfirst.com https://www.google-analytics.com *.pendo.io pendo-static-5086498069413888.storage.googleapis.com *.browser-intake-datadoghq.com;frame-ancestors 'self' app.pendo.io https://*.radarfirst.com https://*.my.salesforce.com/;style-src 'self' 'unsafe-inline' *.product-radar.radarfirst.com https://fonts.googleapis.com app.pendo.io cdn.pendo.io pendo-static-5086498069413888.storage.googleapis.com;worker-src 'self' blob:;default-src 'self';font-src 'self' data: https://*.wistia.com fonts.gstatic.com;frame-src 'self' *.pendo.io https://*.radarfirst.com https://fast.wistia.com https://fast.wistia.net https://*.my.salesforce.com/ *.statuspage.io;form-action 'self' https://*.my.salesforce.com/;img-src 'self' data: https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net *.product-radar.radarfirst.com https://www.google-analytics.com cdn.pendo.io app.pendo.io pendo-static-5086498069413888.storage.googleapis.com data.pendo.io *.wistia.com https://cdn.redoc.ly;media-src 'self' blob: data: https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net;object-src 'none';script-src 'self' 'nonce-M2U2YWFiNGMtODZiNi00ZTljLWE3NjktMzQ0MGI4Yzg0NmM0' https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net *.radarfirst.com https://www.google-analytics.com https://ssl.google-analytics.com app.pendo.io pendo-io-static.storage.googleapis.com cdn.pendo.io data.pendo.io pendo-static-5086498069413888.storage.googleapis.com *.statuspage.io *.datadoghq-browser-agent.com;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
microphone=(), camera=()
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports