Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=surface.com
Issuer
C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 04
Valid From
November 07, 2025
Valid Until
May 06, 2026
131 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA384-RSA
SHA-256 Fingerprint
F6:CE:50:08:B6:5A:99:46:C1:7F:87:4F:68:56:1B:2F:11:BD:CB:45:B0:D4:11:12:FE:95:E6:69:E6:8E:3D:40
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +10 more
default-src *;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.microsoft.com js.monitor.azure.com dc.services.visualstudio.com try-ppe.dot.net aznb-ame-prod.azureedge.net client-api.arkoselabs.com markdowneditor-public-e0gpfpcwcbbze3ag.b01.azurefd.net markdowneditor-external-Public-fmgmfefddycxdmfj.b01.azurefd.net h64.online-metrix.net;style-src 'self' 'unsafe-inline' *.microsoft.com aznb-ame-prod.azureedge.net try-ppe.dot.net markdowneditor-public-e0gpfpcwcbbze3ag.b01.azurefd.net markdowneditor-external-Public-fmgmfefddycxdmfj.b01.azurefd.net;img-src * data: blob:;frame-ancestors docs.microsoft.com *.docs.microsoft.com learn.microsoft.com *.learn.microsoft.com labclient.labondemand.com portal.azure.com *.portal.azure.com portal.azure.us portal.azure.cn ai.azure.com *.ai.azure.com learn-video.azurefd.net docs.azure.cn *.onecloud.azure-test.net *.sharepoint.com localhost:3000;worker-src 'self' blob: *.microsoft.com aznb-ame-prod.azureedge.net;form-action 'self' *.microsoft.com *.azure.cn *.pearsonvue.com;media-src 'self' blob: *.microsoft.com *.azure.cn videoencodingpublic-hgeaeyeba8gycee3.b01.azurefd.net videoencodingpubdevwus.blob.core.windows.net videoencodingpublicwus.blob.core.windows.net;base-uri 'self';font-src 'self' https: data:;object-src 'none';script-src-attr 'none';upgrade-insecure-requests
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
187 domains
msdn.com
feedback.msdn.com
www.msdn.com
425show.dev
www.425show.dev
ambetion.be
www.ambetion.be
ambetion.digital
www.ambetion.digital
azurecontainerapp.com
azurecontainerapp.dev
azurecontainerapp.io
azurecontainerapp.net
azurecontainerapps.dev
azurecontainerapps.io
azurecosmosdb.com
blog.azuremaps.com
docs.azuremaps.com
updates.azuremaps.com
bellavite.org
bogdanss.com
businesscentral.dk
www.businesscentral.dk
cloudchampions11.com
archive.codeplex.com
codeplex.com
codeplex.net
codeplex.org
codeplex.ru
www.codeplex.ru
containers.dev
contextualiq.com
www.contextualiq.com
csshybrid.com
cssmigration.com
cupposunshine.com
d365iom.com
dallasdragon.com
www.dallasdragon.com
dallasdragon.org
www.dallasdragon.org
demoaccsm.com
digitalambetion.be
www.digitalambetion.be
digitalambetion.com
digitalambition.be
www.digitalambition.be
blog.dot.net
blogs.dot.net
dotnetpodcasts.com
dugodaj.com
www.dugodaj.com
dynamics.com
eenvoudig.nu
www.eenvoudig.nu
exchangehybrid.com
exchangehybrid.in
fluentui.dev
www.fluentui.dev
gears.gg
www.gears.gg
gears5.com
www.gears5.com
live.gearsofwar.com
gearspop.com
www.gearspop.com
gearstactics.com
www.gearstactics.com
gigjam.com
www.gigjam.com
gotcosmos.com
hololens.com
www.hololens.com
imaginecup.pl
www.imaginecup.pl
explore.live.com
maquette.ms
www.maquette.ms
mhybrid.cz
microsoft.az
microsoft.be
microsoft.by
microsoft.ca
www.microsoft.ca
microsoft.cat
microsoft.ch
microsoft.cl
microsoft.cz
www.microsoft.cz
microsoft.dk
microsoft.ee
microsoft.es
microsoft.eu
www.microsoft.eu
microsoft.fi
microsoft.ge
microsoft.hu
microsoft.is
microsoft.it
www.microsoft.it
microsoft.jp
www.microsoft.jp
microsoft.lt
microsoft.lu
microsoft.lv
microsoft.md
microsoft.pl
www.microsoft.pl
microsoft.pt
microsoft.ro
microsoft.rs
microsoft.ru
www.microsoft.ru
microsoft.se
microsoft.si
microsoft.tv
microsoft.ua
microsoft.uz
microsoft.vn
microsoftcloud.com
www.microsoftcloud.com
blog.microsoftedge.com
bugs.microsoftedge.com
changelog.microsoftedge.com
data.microsoftedge.com
dev.microsoftedge.com
issues.microsoftedge.com
microsoftedge.com
status.microsoftedge.com
testdrive.microsoftedge.com
www.microsoftedge.com
microsoftfederal.com
microsoftgamedev.com
mmynte.es
www.mmynte.es
mnc.ms
www.mnc.ms
msftgamedev.com
www.msftgamedev.com
msftgamedeveloper.com
msgamedev.com
www.msgamedev.com
msgamedev.net
www.msgamedev.net
msgamedev.org
www.msgamedev.org
msgamedeveloper.com
msgamedevelopment.com
nuget.ms
www.nuget.ms
olxwiki.com
www.olxwiki.com
www.pandoralabs.pt
qir-alliance.com
qir-alliance.org
qiralliance.com
qiralliance.org
ratify.sh
www.remix3d.com
rnmst1.com
skype.tv
www.skype.tv
myservice.surface.com
surface.com
www.surface.com
surfacepreskoly.sk
toycorp.org
typescriptlang.org
vanguardoutrider.com
vivaonboardingapp.dev
hardwaredev.windows.com
it.windows.com
itpro.windows.com
windows.com
www.windows.com
windows.nl
www.windows.nl
windowscontinuum.com
windowsmarketplace.com
www.windowsmarketplace.com
windowsuglysweater.com
winhec.com
www.winhec.com
winhec.net
www.winhec.net
myservice.xbox.com
xbox.com
Other domains in certificate