85/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=New York, L=New York, O=Yahoo Holdings Inc., CN=assist.aol.com
Issuer
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA
Valid From
August 21, 2025
Valid Until
February 11, 2026 89 days
Public Key
ECDSA 256 bit (P-256) Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CD:CC:38:4F:8F:74:3F:24:9A:3D:A2:DA:BF:07:22:C5:47:35:93:3C:F6:9C:A6:73:CB:E1:0B:8E:1B:D2:0B:DF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.0 TLS 1.1 TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)
Warnings
  • TLS 1.1 is deprecated and should be disabled
  • TLS 1.0 is deprecated and should be disabled

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Weak
frame-ancestors; sandbox; report-uri
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

86 domains
checkout.yahoo.com mysubscriptions.yahoo.com plans.yahoo.com subscriptions.yahoo.com *.checkout.yahoo.com *.mysubscriptions.yahoo.com *.plans.yahoo.com *.subscriptions.yahoo.com checkout.finance.yahoo.com checkout.mail.yahoo.com mysubscriptions.finance.yahoo.com mysubscriptions.mail.yahoo.com *.checkout.finance.yahoo.com *.checkout.mail.yahoo.com *.mysubscriptions.finance.yahoo.com *.mysubscriptions.mail.yahoo.com qa.uk.subscriptions.yahoo.com

Other domains in certificate

myaccount.aol.ca *.myaccount.aol.ca
help.aol.co.uk *.help.aol.co.uk myaccount.aol.co.uk *.myaccount.aol.co.uk payments.aol.co.uk *.payments.aol.co.uk
assist.aol.com *.assist.aol.com beta.aol.com *.beta.aol.com blog.productcentral.aol.com *.blog.productcentral.aol.com *.checkout.aol.com checkoutnow.aol.com *.checkoutnow.aol.com communities.aol.com discover.aol.com *.discover.aol.com fr.moncompte.aol.com *.fr.moncompte.aol.com get.aol.com *.get.aol.com getonline.aol.com *.getonline.aol.com help.aol.com *.help.aol.com mailconsent.aol.com myaccount.aol.com *.myaccount.aol.com mybenefits.aol.com *.mybenefits.aol.com myservices.aol.com *.myservices.aol.com mysubscriptions.aol.com *.mysubscriptions.aol.com obi.stage.communities.aol.com payments.aol.com *.payments.aol.com plans.aol.com *.plans.aol.com productcentral.aol.com *.productcentral.aol.com qa.communities.aol.com shield.aol.com *.shield.aol.com
desktop.aol.de *.desktop.aol.de hilfe.aol.de *.hilfe.aol.de meinkonto.aol.de *.meinkonto.aol.de
assistance.aol.fr *.assistance.aol.fr
help.compuserve.com *.help.compuserve.com myaccount.compuserve.com *.myaccount.compuserve.com payments.compuserve.com *.payments.compuserve.com
helpconnect.netscape.com *.helpconnect.netscape.com *.helpisp.netscape.com myaccount.netscape.com *.myaccount.netscape.com mysubscriptions.isp.netscape.com paymentsconnect.netscape.com *.paymentsconnect.netscape.com