88/100 SECURITY SCORE

Certificate Information

Subject
UNKNOWN={:asn1_OPENTYPE, <<12, 20, 80, 114, 105, 118, 97, 116, 101, 32, 79, 114, 103, 97, 110, 105, 122, 97, 116, 105, 111, 110>>}, UNKNOWN={:asn1_OPENTYPE, <<19, 2, 85, 83>>}, UNKNOWN={:asn1_OPENTYPE, "\f\nCalifornia"}, UNKNOWN=C0806592, C=US, ST=California, L=Cupertino, O=Apple Inc., CN=itunes.apple.com
Issuer
C=US, O=Apple Inc., CN=Apple Public EV Server RSA CA 1 - G1
Valid From
February 10, 2026
Valid Until
August 19, 2026 148 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
20:03:0F:F7:DF:AF:DE:A1:B2:B0:10:F5:6F:1F:EC:DB:E2:AC:0A:5A:94:02:99:78:E3:D6:74:C6:A7:21:98:6C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
upgrade-insecure-requests; default-src; img-src; +7 more Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

72 domains
apps.apple.com books.apple.com configuration.apple.com itunes.apple.com music.apple.com podcasts.apple.com tv.apple.com videos.apple.com amp-api-edge.apps.apple.com amp-api-edge.music.apple.com amp-api-search-edge.apps.apple.com api-edge.apps.apple.com api.apps.apple.com api.books.apple.com api.edu.apple.com api.itunes.apple.com api.music.apple.com api.podcasts.apple.com api.videos.apple.com atve.tv.apple.com bookkeeper.itunes.apple.com desktop-music-legacy.itunes.apple.com desktop-store.itunes.apple.com edge.itunes.apple.com init.itunes.apple.com pd.itunes.apple.com radio-activity.itunes.apple.com radio-quickplay.itunes.apple.com radio-services.itunes.apple.com radio.itunes.apple.com sb.music.apple.com sb.tv.apple.com se-edge.itunes.apple.com se.itunes.apple.com search.itunes.apple.com sf-api-token-service.itunes.apple.com siri-search.itunes.apple.com sp.itunes.apple.com su.itunes.apple.com sync.itunes.apple.com tf-feedback.itunes.apple.com upp.itunes.apple.com uts-api-siri.itunes.apple.com vocabulary.itunes.apple.com

Other domains in certificate

a1.mzstatic.com a2.mzstatic.com a3.mzstatic.com a4.mzstatic.com a5.mzstatic.com accertify.mzstatic.com apps.mzstatic.com assets-mercury.mzstatic.com b1.mzstatic.com b2.mzstatic.com b3.mzstatic.com b4.mzstatic.com b5.mzstatic.com images-mercury.mzstatic.com is1-ssl.mzstatic.com is2-ssl.mzstatic.com is3-ssl.mzstatic.com is4-ssl.mzstatic.com is5-ssl.mzstatic.com itc.mzstatic.com metrics.mzstatic.com s.mzstatic.com s1.mzstatic.com s2.mzstatic.com s3.mzstatic.com s4.mzstatic.com s5.mzstatic.com store.mzstatic.com