Open
Cached
·
just now
81/100
SECURITY SCORE
Certificate Information
Subject
C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.lazada.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign GCC R3 OV TLS CA 2024
Valid From
June 06, 2025
Valid Until
July 08, 2026
241 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
ED:BD:78:C1:73:79:EC:CF:91:AB:AF:AE:D6:B9:AF:D8:F6:BD:52:5B:0B:56:8B:F8:50:9B:E3:23:35:E7:55:A7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
Forward Secrecy
Limited
(Check cipher configuration)
Warnings
- • TLS 1.3 is not supported (recommended)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
147 domains
lazada.co.th
*.lazada.co.th
*.lazadapay.co.th
*.adsense.lazada.co.th
*.education.lazada.co.th
*.sellercenter-staging.lazada.co.th
*.sellercenter.lazada.co.th
*.zal.lazada.co.th
asterism-studio.com
*.adsense.lazada.co.id
*.education.lazada.co.id
lazada.co.id
*.lazada.co.id
*.lazadapay.co.id
*.lazlogistics.co.id
*.llportal.co.id
*.sellercenter-staging.lazada.co.id
*.sellercenter.lazada.co.id
lazada.com.hk
*.adsense.lazada.com.my
*.alimebot.lazada.com.my
*.beta.lazada.com.my
*.education.lazada.com.my
lazada.com.my
*.lazada.com.my
*.lazadapay.com.my
*.llportal.com.my
*.sellercenter-staging.lazada.com.my
*.sellercenter.lazada.com.my
*.adsense.lazada.com.ph
*.alimebot.lazada.com.ph
*.education.lazada.com.ph
lazada.com.ph
*.lazada.com.ph
*.lazadapay.com.ph
llportal.com.ph
*.llportal.com.ph
*.metrocourier-inc.com.ph
*.sellercenter-staging.lazada.com.ph
*.sellercenter.lazada.com.ph
fxm.so
*.fxm.so
*.lazlogistics.in.th
*.llportal.in.th
*.lazada-seller.cn
*.sellercenter-id-staging.lazada-seller.cn
*.sellercenter-id.lazada-seller.cn
*.sellercenter-my-staging.lazada-seller.cn
*.sellercenter-my.lazada-seller.cn
*.sellercenter-ph-staging.lazada-seller.cn
*.sellercenter-ph.lazada-seller.cn
*.sellercenter-sg-staging.lazada-seller.cn
*.sellercenter-sg.lazada-seller.cn
*.sellercenter-th-staging.lazada-seller.cn
*.sellercenter-th.lazada-seller.cn
*.sellercenter-vn-staging.lazada-seller.cn
*.sellercenter-vn.lazada-seller.cn
*.fc.lazada.cn
lazada.cn
*.lazada.cn
*.3plportal.lazada.com
*.admin2.lazada.com
*.api.lazada.com
*.aut.lazada.com
*.beta-workstation.lazada.com
*.datascience.lazada.com
*.dev-arise-es.lazada.com
*.dev-arise-fr.lazada.com
*.dev-arise.lazada.com
*.dev.lazada.com
*.education.lazada.com
*.fc.lazada.com
*.feedback-pre.lazada.com
*.fund-finnet.lazada.com
*.geoserver.lazada.com
*.hec.lazada.com
*.id.lazada.com
*.kh.lazada.com
lazada.com
*.lazada.com
*.lazmall.lazada.com
*.lel.lazada.com
*.live.lazada.com
*.logistics.lazada.com
*.m.lazada.com
*.my.lazada.com
*.orion.lazada.com
*.payment.lazada.com
*.pre-workstation.lazada.com
*.scm.lazada.com
*.sg.lazada.com
*.ut.lazada.com
*.v.lazada.com
*.video.lazada.com
*.wallet-member-prod.lazada.com
*.wallet-payment.lazada.com
*.workstation.lazada.com
*.x-space.lazada.com
lazada.jp
lazada.kr
*.adsense.lazada.sg
*.education.lazada.sg
*.fc.lazada.sg
lazada.sg
*.lazada.sg
*.lazpay.lazada.sg
*.order.lazada.sg
*.pre-edith.lazada.sg
*.pre.lazada.sg
*.rest.lazada.sg
*.sellercenter-staging-redmart.lazada.sg
*.sellercenter-staging.lazada.sg
*.sellercenter.lazada.sg
*.store.lazada.sg
*.adsense.lazada.vn
*.education.lazada.vn
lazada.vn
*.lazada.vn
*.sellercenter-staging.lazada.vn
*.sellercenter.lazada.vn
*.lazadapay.sg
*.lazadapay.vn
lazcdn.com
*.lazcdn.com
lazlogistics.my
*.lazlogistics.my
lazlogistics.ph
*.lazlogistics.ph
lazlogistics.sg
*.lazlogistics.sg
lazlogistics.vn
*.lazlogistics.vn
*.lel.asia
llportal.sg
*.llportal.sg
llportal.vn
*.llportal.vn
*.lzd.co
miravia.es
*.protocol-adapter.miravia.es
*.alpha.redmart.com
redmart.com
*.redmart.com
*.h5accs.taobao.global
*.h5accs.taobao.tw
msgacs-m.taobao.tw
msgacs-wapa.taobao.tw
Other domains in certificate