Open
Cached
·
just now
88/100
SECURITY SCORE
Certificate Information
Subject
UNKNOWN={:asn1_OPENTYPE, <<12, 20, 80, 114, 105, 118, 97, 116, 101, 32, 79, 114, 103, 97, 110, 105, 122, 97, 116, 105, 111, 110>>}, UNKNOWN={:asn1_OPENTYPE, <<19, 2, 85, 83>>}, UNKNOWN={:asn1_OPENTYPE, "\f\nCalifornia"}, UNKNOWN=C0806592, C=US, ST=California, L=Cupertino, O=Apple Inc., CN=itunes.apple.com
Issuer
C=US, O=Apple Inc., CN=Apple Public EV Server RSA CA 1 - G1
Valid From
February 10, 2026
Valid Until
August 19, 2026
148 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
20:03:0F:F7:DF:AF:DE:A1:B2:B0:10:F5:6F:1F:EC:DB:E2:AC:0A:5A:94:02:99:78:E3:D6:74:C6:A7:21:98:6C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
72 domains
apps.apple.com
books.apple.com
configuration.apple.com
itunes.apple.com
music.apple.com
podcasts.apple.com
tv.apple.com
videos.apple.com
amp-api-edge.apps.apple.com
amp-api-edge.music.apple.com
amp-api-search-edge.apps.apple.com
api-edge.apps.apple.com
api.apps.apple.com
api.books.apple.com
api.edu.apple.com
api.itunes.apple.com
api.music.apple.com
api.podcasts.apple.com
api.videos.apple.com
atve.tv.apple.com
bookkeeper.itunes.apple.com
desktop-music-legacy.itunes.apple.com
desktop-store.itunes.apple.com
edge.itunes.apple.com
init.itunes.apple.com
pd.itunes.apple.com
radio-activity.itunes.apple.com
radio-quickplay.itunes.apple.com
radio-services.itunes.apple.com
radio.itunes.apple.com
sb.music.apple.com
sb.tv.apple.com
se-edge.itunes.apple.com
se.itunes.apple.com
search.itunes.apple.com
sf-api-token-service.itunes.apple.com
siri-search.itunes.apple.com
sp.itunes.apple.com
su.itunes.apple.com
sync.itunes.apple.com
tf-feedback.itunes.apple.com
upp.itunes.apple.com
uts-api-siri.itunes.apple.com
vocabulary.itunes.apple.com
a1.mzstatic.com
a2.mzstatic.com
a3.mzstatic.com
a4.mzstatic.com
a5.mzstatic.com
accertify.mzstatic.com
apps.mzstatic.com
assets-mercury.mzstatic.com
b1.mzstatic.com
b2.mzstatic.com
b3.mzstatic.com
b4.mzstatic.com
b5.mzstatic.com
images-mercury.mzstatic.com
is1-ssl.mzstatic.com
is2-ssl.mzstatic.com
is3-ssl.mzstatic.com
is4-ssl.mzstatic.com
is5-ssl.mzstatic.com
itc.mzstatic.com
metrics.mzstatic.com
s.mzstatic.com
s1.mzstatic.com
s2.mzstatic.com
s3.mzstatic.com
s4.mzstatic.com
s5.mzstatic.com
store.mzstatic.com
Other domains in certificate