Open
Cached
·
just now
81/100
SECURITY SCORE
Certificate Information
Subject
CN=nebius.com
Issuer
C=US, O=DigiCert, Inc., CN=GeoTrust Global TLS RSA4096 SHA256 2022 CA1
Valid From
August 22, 2025
Valid Until
February 22, 2026
55 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
27:6B:2D:BE:47:97:EC:CF:37:70:F0:ED:F4:41:AF:86:65:6D:E4:99:45:B7:7F:65:03:56:1F:DA:FF:A1:D3:0F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Basic
default-src; script-src; script-src-elem; +11 more
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://*.hs-analytics.net https://*.hsadspixel.net https://js.hscta.net https://js-eu1.hscta.net https://*.hubspot.com https://static.hsappstatic.net https://*.usemessages.com https://*.hs-banner.com https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net https://*.hubspot.net https://*.hscollectedforms.net https://*.hsleadflows.net https://*.hsforms.net https://*.hsforms.com https://*.hs-scripts.com https://*.hubspotfeedback.com https://feedback.hubapi.com https://feedback-eu1.hubapi.com https://*.hotjar.com; script-src-elem 'self' 'unsafe-inline' https://boards.greenhouse.io https://job-boards.greenhouse.io https://*.googletagmanager.com https://*.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://www.gstatic.com https://*.clarity.ms https://*.hsforms.net https://*.hs-scripts.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hsadspixel.net https://*.hubspot.com https://js.hscta.net https://js-eu1.hscta.net https://static.hsappstatic.net https://*.usemessages.com https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net https://*.hubspot.net https://*.hscollectedforms.net https://*.hsleadflows.net https://connect.facebook.net https://snap.licdn.com https://www.redditstatic.com https://analytics.tiktok.com https://*.hotjar.com https://t.contentsquare.net https://static.ads-twitter.com; style-src 'self' 'unsafe-inline' https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net https://cdn2.hubspot.net https://*.hotjar.com; object-src 'self' data:; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' https://nebius.directus.app *.nebius.ai assets.nebius.com data: https://*.googletagmanager.com https://*.google-analytics.com https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.analytics.google.com https://*.g.doubleclick.net https://pagead2.googlesyndication.com https://google.com https://*.google.com https://*.google.co.uk https://*.google.co.in https://*.google.com.au https://*.google.ca https://*.google.de https://*.google.fr https://*.google.it https://*.google.es https://*.google.co.jp https://*.google.pl https://*.google.nl https://*.google.se https://*.google.no https://*.google.dk https://*.google.fi https://*.google.ch https://*.google.cz https://*.google.hu https://*.google.ge https://*.bing.com https://*.clarity.ms https://js.hscta.net https://js-eu1.hscta.net https://no-cache.hubspot.com https://*.hubspot.com https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net https://*.hubspot.net https://*.hsforms.net https://*.hsforms.com https://*.facebook.com https://px.ads.linkedin.com https://www.linkedin.com https://alb.reddit.com https://*.hotjar.com https://*.twitter.com https://t.co; media-src 'self' https://nebius.directus.app *.nebius.ai assets.nebius.com; font-src 'self' data: https://fonts.gstatic.com https://*.hotjar.com; child-src 'self' www.youtube.com https://nebius.directus.app *.nebius.ai assets.nebius.com https://*.hsforms.com; frame-src 'self' www.youtube.com https://nebius.directus.app *.nebius.ai assets.nebius.com https://boards.greenhouse.io https://job-boards.greenhouse.io https://*.googletagmanager.com https://td.doubleclick.net https://*.google.com https://*.hubspot.com https://*.hs-sites.com https://*.hs-sites-eu1.com https://*.hubspot.net https://play.hubspotvideo.com https://play-eu1.hubspotvideo.com https://*.hsforms.net https://*.hsforms.com https://*.facebook.com https://charts3.equitystory.com https://irpages2.eqs.com; frame-ancestors 'self' https://nebius.directus.app *.nebius.ai assets.nebius.com; connect-src 'self' https://nebius.directus.app *.nebius.ai assets.nebius.com https://boards-api.greenhouse.io https://googletagmanager.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://google.com https://*.google.com https://*.google.co.uk https://*.google.co.in https://*.google.com.au https://*.google.ca https://*.google.de https://*.google.fr https://*.google.it https://*.google.es https://*.google.co.jp https://*.google.pl https://*.google.nl https://*.google.se https://*.google.no https://*.google.dk https://*.google.fi https://*.google.ch https://*.google.cz https://*.google.hu https://*.google.ge https://td.doubleclick.net https://*.clarity.ms https://hubspot-forms-static-embed-eu1.s3.amazonaws.com https://*.hubapi.com https://js.hscta.net https://js-eu1.hscta.net https://*.hubspot.com https://*.hs-banner.com https://*.hscollectedforms.net https://*.hsforms.com https://*.facebook.com https://px.ads.linkedin.com https://pixel-config.reddit.com https://www.redditstatic.com https://analytics.tiktok.com https://gw.stape.run https://capig.stape.host https://charts3.equitystory.com https://irpages2.eqs.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.twitter.com https://*.typesense.net;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Incident Reporting
mailto:[email protected]
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 4 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'issuewild' records to control wildcard certificate issuance