Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=California, O=The Walt Disney Company, CN=editions.espn.com
Issuer
C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
Valid From
November 10, 2025
Valid Until
November 10, 2026
363 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DD:77:9A:75:DD:1D:EE:20:46:71:F5:11:09:1C:DA:82:EC:0E:52:F1:25:17:6E:F5:CE:46:83:C3:74:40:79:04
Alternative Names
Security Configuration
TLS Protocols
TLS 1.0
TLS 1.1
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
Warnings
- • TLS 1.1 is deprecated and should be disabled
- • TLS 1.0 is deprecated and should be disabled
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Significantly strengthen CSP directives
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
98 domains
espn.com
*.espn.com
editions.espn.com
*.api.espn.co.cr
espn.co.cr
*.espn.co.cr
*.fan.api.espn.co.cr
fan.core.api.espn.co.cr
*.api.espn.com.do
espn.com.do
*.espn.com.do
*.fan.api.espn.com.do
fan.core.api.espn.com.do
*.api.espn.com.ec
espn.com.ec
*.espn.com.ec
*.fan.api.espn.com.ec
fan.core.api.espn.com.ec
*.api.espn.com.gt
espn.com.gt
*.espn.com.gt
*.fan.api.espn.com.gt
fan.core.api.espn.com.gt
*.api.espn.com.pa
espn.com.pa
*.espn.com.pa
*.fan.api.espn.com.pa
fan.core.api.espn.com.pa
*.api.espn.com.sg
espn.com.sg
*.espn.com.sg
*.fan.api.espn.com.sg
fan.core.api.espn.com.sg
*.api.espn.com.uy
espn.com.uy
*.espn.com.uy
*.fan.api.espn.com.uy
fan.core.api.espn.com.uy
*.api.espn.cl
espn.cl
*.espn.cl
fan.core.api.espn.cl
*.api.espn.co.uk
espn.co.uk
*.espn.co.uk
fan.core.api.espn.co.uk
*.api.espn.com.ar
espn.com.ar
*.espn.com.ar
fan.core.api.espn.com.ar
*.api.espn.com.au
espn.com.au
*.espn.com.au
fan.core.api.espn.com.au
*.api.espn.com.br
espn.com.br
*.espn.com.br
fan.core.api.espn.com.br
*.api.espn.com.co
espn.com.co
*.espn.com.co
fan.core.api.espn.com.co
*.api.espn.com.mx
espn.com.mx
*.espn.com.mx
fan.core.api.espn.com.mx
*.api.espn.com.pe
espn.com.pe
*.espn.com.pe
*.fan.api.espn.com.pe
fan.core.api.espn.com.pe
*.api.espn.com.ve
espn.com.ve
*.espn.com.ve
*.fan.api.espn.com.ve
fan.core.api.espn.com.ve
*.api.espn.es
espn.es
*.espn.es
*.fan.api.espn.es
fan.core.api.espn.es
*.api.espn.in
espn.in
*.espn.in
fan.core.api.espn.in
*.api.espn.nl
espn.nl
*.espn.nl
*.fan.api.espn.nl
fan.core.api.espn.nl
espn.ph
*.espn.ph
*.fan.api.espn.ph
fan.core.api.espn.ph
espndeportes.com
*.espndeportes.com
espn.go.com
*.espn.go.com
Other domains in certificate