SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Hostname Mismatch - certificate is issued for cdn.docusign.com, 1ds-ssg-starter-kit.docusign.com, account.docusign.com, am.eu.account.docusign.com, apirequestbuilder-s.docusign.com, apirequestbuilder.docusign.com, app-au.docusign.com, app-ca.docusign.com, app-eu.docusign.com, not for apps.docusign.com.edgekey.net
Open
Cached
·
just now
75/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
UNKNOWN={:asn1_OPENTYPE, <<19, 2, 85, 83>>}, UNKNOWN={:asn1_OPENTYPE, <<19, 8, 68, 101, 108, 97, 119, 97, 114, 101>>}, UNKNOWN={:asn1_OPENTYPE, <<12, 20, 80, 114, 105, 118, 97, 116, 101, 32, 79, 114, 103, 97, 110, 105, 122, 97, 116, 105, 111, 110>>}, UNKNOWN=5711317, C=US, ST=California, L=San Francisco, O=Docusign, Inc., CN=cdn.docusign.com
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1
Valid From
April 09, 2026
Valid Until
October 06, 2026
147 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
25:9D:29:CD:C5:A3:9F:0A:BD:FB:74:A8:76:16:F7:E2:27:9A:43:E7:B6:A1:77:73:B0:7D:CF:5B:35:06:9E:7B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
95 domains
go.docusign.ca
www.docusign.ca
go.docusign.co.uk
www.docusign.co.uk
go.docusign.co.za
1ds-ssg-starter-kit.docusign.com
account.docusign.com
am.eu.account.docusign.com
apirequestbuilder-s.docusign.com
apirequestbuilder.docusign.com
app-au.docusign.com
app-ca.docusign.com
app-eu.docusign.com
app-jp.docusign.com
app.docusign.com
appcenter.docusign.com
apps-au.docusign.com
apps-ca.docusign.com
apps-eu.docusign.com
apps-jp.docusign.com
apps-us.docusign.com
apps.docusign.com
au.account.docusign.com
au.wallet.account.docusign.com
ca.account.docusign.com
ca.wallet.account.docusign.com
cdn.docusign.com
certs.docusign.com
ch.na.account.docusign.com
compliance.docusign.com
da.na.account.docusign.com
decom.docusign.com
developers.docusign.com
dxp.docusign.com
ecom-admin.docusign.com
ecom-d.docusign.com
ecom-s.docusign.com
ecom.docusign.com
eu.account.docusign.com
eu.wallet.account.docusign.com
fr.eu.account.docusign.com
go.docusign.com
health.docusign.com
jp.account.docusign.com
js.docusign.com
links.docusign.com
me.au.account.docusign.com
momentum.docusign.com
na.account.docusign.com
na.wallet.account.docusign.com
pages.docusign.com
partners.docusign.com
postsign.docusign.com
qc.ca.account.docusign.com
s1-au.apps.docusign.com
s1-ca.apps.docusign.com
s1-eu.apps.docusign.com
s1-jp.apps.docusign.com
s1-us.apps.docusign.com
s2-au.apps.docusign.com
s2-ca.apps.docusign.com
s2-eu.apps.docusign.com
s2-jp.apps.docusign.com
s2-us.apps.docusign.com
s3-us.apps.docusign.com
s4-us.apps.docusign.com
se.na.account.docusign.com
secure.docusign.com
statusold.docusign.com
suporte.docusign.com
support.docusign.com
sy.au.account.docusign.com
to.ca.account.docusign.com
wallet.account.docusign.com
www.docusign.com
go.docusign.com.au
www.docusign.com.au
go.docusign.com.br
www.docusign.com.br
docusign.com.es
go.docusign.com.es
go.docusign.de
www.docusign.de
go.docusign.fr
www.docusign.fr
go.docusign.in
www.docusign.in
go.docusign.it
go.docusign.jp
www.docusign.jp
go.docusign.mx
www.docusign.mx
go.docusign.nl
www.docusign.nl
go.docusign.sg