Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
CN=auth.cloud.redocly.com
Issuer
C=US, O=Let's Encrypt, CN=E8
Valid From
January 12, 2026
Valid Until
April 12, 2026
86 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
5C:ED:D6:AE:3D:9F:71:49:E9:C0:DC:ED:A3:55:89:28:13:DF:20:1E:43:8E:AE:0D:79:D2:D7:55:26:27:64:F9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; upgrade-insecure-requests; require-trusted-types-for; +12 more
default-src 'none';upgrade-insecure-requests;require-trusted-types-for 'script';img-src 'self' https: data: blob: chat.frontapp.com chat-assets.frontusercontent.com www.googletagmanager.com https://googletagmanager.com https://*.google-analytics.com https://*.googletagmanager.com;script-src 'self' 'report-sample' 'wasm-eval' 'wasm-unsafe-eval' 'nonce-T+lBopeN7lGEutztasvbTNWetDHQLQ2QLwRp2Le4i2M=' blob: https://www.googletagmanager.com https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleanalytics.com https://*.google-analytics.com https://*.analytics.google.com https://ssl.google-analytics.com https://www.googleoptimize.com https://optimize.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.rudderlabs.com https://assets.calendly.com https://cdn.redoc.ly https://stats.pusher.com https://snap.licdn.com https://*.frontapp.com https://framepay.rebilly.com https://cdn.rebilly.com *.pusher.com *.pusherapp.com https://polyfill-fastly.io https://cdn.jsdelivr.net;media-src 'self' https://*.frontapp.com;style-src 'self' 'unsafe-inline' 'report-sample' fonts.googleapis.com https://tagmanager.google.com https://googletagmanager.com https://framepay.rebilly.com https://optimize.google.com https://fonts.googleapis.com https://cdn.jsdelivr.net data: blob:;font-src 'self' data: fonts.gstatic.com https://script.hotjar.com https://chat-assets.frontapp.com https://fonts.gstatic.com https://cdn.jsdelivr.net;connect-src 'self' https://app.cloud.redocly.com https://auth.cloud.redocly.com https://www.google-analytics.com https://vc.hotjar.io:* https://surveystats.hotjar.io wss://*.hotjar.com https://*.hotjar.com:* https://api.rebilly.com https://api-sandbox.rebilly.com https://sentry.io https://*.rudderlabs.com https://*.dataplane.rudderstack.com https://auth.redocly.com https://*.ingest.sentry.io wss://ws.pusherapp.com wss://*.pusher.com https://*.redocly.com https://redocly.com https://*.redocly.app https://*.wysiwyg.cloud.redocly.com https://cdn.jsdelivr.net chat-assets.frontapp.com chat.frontapp.com us-west-1-chat-server.frontapp.com us-west-2-chat-server.frontapp.com eu-west-1-chat-server.frontapp.com https://chat-assets.frontusercontent.com wss://front-us-realtime.ably.io wss://*.ably-realtime.com https://internet-up.ably-realtime.com wss://front-eu-realtime.ably.io https://chat-webhook.frontapp.com *.bugsnag.com https://*.browser-intake-datadoghq.com www.googletagmanager.com www.google.com;frame-src 'self' https://vars.hotjar.com https://calendly.com https://redocly.typeform.com https://*.redocly.com https://*.redocly.app https://*.wysiwyg.cloud.redocly.com https://*.portal.cloud.redocly.com https://*.preview.cloud.redocly.com https://optimize.google.com https://framepay.rebilly.com https://forms.secure-payments.app https://cdn.rebilly.com;manifest-src 'self';frame-ancestors 'self' https://*.redocly.com https://*.redocly.app https://*.wysiwyg.cloud.redocly.com;object-src 'none';base-uri 'self';report-uri https://o9qesb1t75.execute-api.us-east-1.amazonaws.com/default/CSP-reports-BH
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
geolocation=(), camera=(), microphone=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports