Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=California, O=The Walt Disney Company, CN=editions.espn.com
Issuer
C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
Valid From
November 10, 2025
Valid Until
November 10, 2026 363 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DD:77:9A:75:DD:1D:EE:20:46:71:F5:11:09:1C:DA:82:EC:0E:52:F1:25:17:6E:F5:CE:46:83:C3:74:40:79:04
Alternative Names

Security Configuration

TLS Protocols
TLS 1.0 TLS 1.1 TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)
Warnings
  • TLS 1.1 is deprecated and should be disabled
  • TLS 1.0 is deprecated and should be disabled

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

98 domains
espn.com *.espn.com editions.espn.com

Other domains in certificate

*.api.espn.co.cr espn.co.cr *.espn.co.cr *.fan.api.espn.co.cr fan.core.api.espn.co.cr
*.api.espn.com.do espn.com.do *.espn.com.do *.fan.api.espn.com.do fan.core.api.espn.com.do
*.api.espn.com.ec espn.com.ec *.espn.com.ec *.fan.api.espn.com.ec fan.core.api.espn.com.ec
*.api.espn.com.gt espn.com.gt *.espn.com.gt *.fan.api.espn.com.gt fan.core.api.espn.com.gt
*.api.espn.com.pa espn.com.pa *.espn.com.pa *.fan.api.espn.com.pa fan.core.api.espn.com.pa
*.api.espn.com.sg espn.com.sg *.espn.com.sg *.fan.api.espn.com.sg fan.core.api.espn.com.sg
*.api.espn.com.uy espn.com.uy *.espn.com.uy *.fan.api.espn.com.uy fan.core.api.espn.com.uy
*.api.espn.cl espn.cl *.espn.cl fan.core.api.espn.cl
*.api.espn.co.uk espn.co.uk *.espn.co.uk fan.core.api.espn.co.uk
*.api.espn.com.ar espn.com.ar *.espn.com.ar fan.core.api.espn.com.ar
*.api.espn.com.au espn.com.au *.espn.com.au fan.core.api.espn.com.au
*.api.espn.com.br espn.com.br *.espn.com.br fan.core.api.espn.com.br
*.api.espn.com.co espn.com.co *.espn.com.co fan.core.api.espn.com.co
*.api.espn.com.mx espn.com.mx *.espn.com.mx fan.core.api.espn.com.mx
*.api.espn.com.pe espn.com.pe *.espn.com.pe *.fan.api.espn.com.pe fan.core.api.espn.com.pe
*.api.espn.com.ve espn.com.ve *.espn.com.ve *.fan.api.espn.com.ve fan.core.api.espn.com.ve
*.api.espn.es espn.es *.espn.es *.fan.api.espn.es fan.core.api.espn.es
*.api.espn.in espn.in *.espn.in fan.core.api.espn.in
*.api.espn.nl espn.nl *.espn.nl *.fan.api.espn.nl fan.core.api.espn.nl
espn.ph *.espn.ph *.fan.api.espn.ph fan.core.api.espn.ph
espndeportes.com *.espndeportes.com
espn.go.com *.espn.go.com