Open
Cached
·
just now
84/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=microsoft.com
Issuer
C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 04
Valid From
January 07, 2026
Valid Until
July 06, 2026
167 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA384-RSA
SHA-256 Fingerprint
27:34:E0:61:ED:F2:B0:F5:E6:4F:B6:40:B9:3E:CF:63:0C:C7:02:D4:F5:3B:29:8B:EE:89:9B:B4:6C:77:BE:B0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; base-uri; script-src; +12 more
default-src 'none';base-uri 'self' https://res.cdn.office.net/eduactivelearning/public/;script-src 'self' 'report-sample' 'wasm-unsafe-eval' https://res.cdn.office.net/admincenter/admin-main/ https://unpkg.com/@microsoft/ 'sha256-ibcXX1Kr36MlkdnyhtLea8PKKj35bAnteGlsIEhRBnQ=' 'sha256-Paep0fDUfnn3Tfs7Tj3UQEDLrgFLU8AlG7yDcFdSWtE=' https://res.cdn.office.net/eduactivelearning/public/;form-action 'none';font-src https://res-1.cdn.office.net/ https://spoprod-a.akamaihd.net/files/fabric/ https://static2.sharepointonline.com/files/fabric/;style-src 'self' 'report-sample' 'unsafe-inline' https://res.cdn.office.net/eduactivelearning/public/;connect-src https://login.microsoftonline.com https://admin.microsoft.com https://petrol.office.microsoft.com/v1/feedback https://petrol-int.office.microsoft.com/ https://eu.pipe.aria.microsoft.com/ https://browser.pipe.aria.microsoft.com/ https://res.cdn.office.net/eduactivelearning/public/ 'self';child-src 'none';report-uri https://csp.microsoft.com/report/Education-Analytics-PROD;object-src 'none';frame-ancestors https:;upgrade-insecure-requests;img-src data: blob: 'self' https://media.gettyimages.com *;media-src data: blob: 'self' https://res.cdn.office.net/eduactivelearning/public/;frame-src https://login.microsoftonline.com https://microsoft-onmicrosoft-com.access.mcas.ms https://youtube.com https://www.youtube-nocookie.com https://create.kahoot.it https://create.kahoot-experimental.it https://create.kahoot-stage.it https://create.kahoot-qa.it support.office.com 'self';
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Not Authorized
(Potential misconfiguration)
Authorized CAs
Incident Reporting
mailto:[email protected]
CAA Issues
- • CRITICAL: Current certificate issuer 'C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 04' is NOT authorized by CAA records. Authorized CAs: microsoft.com
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'issuewild' records to control wildcard certificate issuance
Subject Alternative Names
178 domains
mlz.do
www.mlz.do
2010office.it
www.2010office.it
adatum.ai
www.adatum.ai
aiandyou.today
www.aiandyou.today
aielectionsaccord.com
www.aielectionsaccord.com
www.applyxboxcreditcard.com
friday.azure.com
demo.azuremaps.com
bestxboxgames.com
www.bestxboxgames.com
book.ms
www.book.ms
boulder-innovations.com
www.boulder-innovations.com
copilotsi.com
www.copilotsi.com
docx.new
www.docx.new
excel.new
www.excel.new
exploresurface.com
www.exploresurface.com
auth.flip.com
help.flip.com
info.flip.com
forzamotorsport.net
rewards.forzamotorsport.net
www.forzamotorsport.net
shop.gearsofwar.com
getlicensingready.com
www.getlicensingready.com
www.getxboxcreditcard.com
www.gh.io
insightstomorrow.com
www.insightstomorrow.com
lakeshore-retail.com
www.lakeshore-retail.com
www.learnxboxcreditcard.com
dev.lobe.ai
www.lobe.ai
login.microsoft
m365copilot.com
www.m365copilot.com
m365telemetry.net
www.m365telemetry.net
makeitgreat.com.au
www.makeitgreat.com.au
airlift.microsoft.com
customers.microsoft.com
microsoft.com
microsoftcopilotstudio.microsoft.com
mybuild.microsoft.com
nonprofitcommunity.microsoft.com
onegdc.microsoft.com
powerusers-staging.microsoft.com
powerusers.microsoft.com
threatintel.microsoft.com
trials.transform.microsoft.com
ux.microsoft.com
ux.uat.microsoft.com
microsoft365copilot.com
microsoftintegrity.com
www.microsoftintegrity.com
microsoftoffice.help
www.microsoftoffice.help
microsoftsolitairecollection.com
www.microsoftsolitairecollection.com
mihsydney.com
www.mihsydney.com
minecraftdungeons.com
www.minecraftdungeons.com
minecrafteducation.net
www.minecrafteducation.net
msthreatintelpodcast.com
www.msthreatintelpodcast.com
new-office.it
www.new-office.it
nuovo-office.it
www.nuovo-office.it
o36ssupport.com
office-2013.it
www.office-2013.it
apc.delve.office.com
can.delve.office.com
delve-gcc.office.com
delve.office.com
df.delve.office.com
eur.delve.office.com
gbr.delve.office.com
gcc.delve.office.com
lam.delve.office.com
msit.delve.office.com
nam.delve.office.com
sfeur.delve.office.com
sfnam.delve.office.com
teamsdemo.office.com
office.download
www.office.download
office.email
www.office.email
office.live
www.office.live
office.microsoft
www.office.microsoft
office.security
www.office.security
office.support
www.office.support
office365-lavoro.it
www.office365-lavoro.it
office365proskoly.cz
www.office365proskoly.cz
office365support.ms
office365support.us
outlook-2013.it
www.outlook-2013.it
outlook2013.it
playxbox.com
www.playxbox.com
powerfuldevs.com
powerpoint.com
www.powerpoint.com
powerpoint.new
www.powerpoint.new
ppt.new
www.ppt.new
pptx.new
www.pptx.new
www.qnamaker.ai
reflect.new
reflect.space
rnicrosoftsupport.com
scottandmarklearn.to
www.scottandmarklearn.to
scottandmarklearnto.com
www.scottandmarklearnto.com
www.thexboxcard.com
thexboxcreditcard.com
www.thexboxcreditcard.com
collectors.tivan.ms
forums.towerborne.com
www.forums.towerborne.com
trym365.com
www.trym365.com
visualstudio.blog
www.visualstudio.blog
vscode-edu.com
www.vscode-edu.com
vscode.education
www.vscode.education
winterstarfall.com
www.winterstarfall.com
word.new
www.word.new
www.office
www.xboxcreditcard.com
www.xboxdesignlab.com
xboxdesignlab.com
www.xboxgamer.com
xboxgamer.com
www.xboxgames.com
xboxgames.com
www.xboxgaming.com
xboxgaming.com
www.xboxplace.com
xboxplace.com
www.xboxplay.com
xboxplay.com
www.xboxrewardscard.com
www.xboxstar.com
xboxstar.com
www.xboxuserresearch.com
xboxuserresearch.com
Other domains in certificate