Open
Cached
·
just now
94/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=surface.com
Issuer
C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 04
Valid From
November 07, 2025
Valid Until
May 06, 2026
131 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA384-RSA
SHA-256 Fingerprint
F6:CE:50:08:B6:5A:99:46:C1:7F:87:4F:68:56:1B:2F:11:BD:CB:45:B0:D4:11:12:FE:95:E6:69:E6:8E:3D:40
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Good
base-uri; font-src; form-action; +12 more
base-uri 'none'; font-src 'self' data: https://*.microsoft.com http://c.s-microsoft.com https://c.s-microsoft.com https://edgestatic.azureedge.net https://edgecdn-embza6g8cacagcbn.z01.azurefd.net https://edgecdn-embza6g8cacagcbn.b02.azurefd.net https://assets.onestore.ms; form-action 'self' https://*.microsoft.com https://*.bing.com; frame-ancestors 'self' https://*.microsoft.com https://*.bing.com chrome-untrusted://dual-search; img-src * data:; object-src 'none'; script-src-attr 'none'; style-src 'self' 'unsafe-inline' https://*.microsoft.com https://statics-marketingsites-wcus-ms-com.akamaized.net https://statics-marketingsites-eus-ms-com.akamaized.net https://statics-marketingsites-neu-ms-com.akamaized.net https://statics-marketingsites-eas-ms-com.akamaized.net https://edgestatic.azureedge.net https://edgecdn-embza6g8cacagcbn.z01.azurefd.net https://edgecdn-embza6g8cacagcbn.b02.azurefd.net https://assets.onestore.ms; script-src 'nonce-EM06ddNMMvMbOGev6bjOPq2p' 'strict-dynamic'; upgrade-insecure-requests; default-src 'self' https://edgestatic.azureedge.net https://edgecdn-embza6g8cacagcbn.z01.azurefd.net https://edgecdn-embza6g8cacagcbn.b02.azurefd.net https://*.microsoft.com; require-trusted-types-for 'script'; connect-src 'self' http://*.microsoft.com https://*.microsoft.com https://*.bing.com https://*.bing.net https://*.clarity.ms https://js.monitor.azure.com https://edgestatic.azureedge.net https://edgecdn-embza6g8cacagcbn.z01.azurefd.net https://edgecdn-embza6g8cacagcbn.b02.azurefd.net https://consentreceiverfd-prod.azurefd.net https://cdn.linkedin.oribi.io https://*.linkedin.com https://*.licdn.com/ https://boost.mediation.trafficmanager.net https://boost-client-czcnbahycxbnamaq.b01.azurefd.net https://*.adnxs.com https://app.adjust.com; frame-src 'self' http://*.microsoft.com https://*.microsoft.com https://*.msn.com https://*.msn.cn https://*.bing.com https://www.youtube-nocookie.com https://microsoft-store-11800745.azurewebsites.net https://*.tiktok.com; media-src 'self' https://edgestatic.azureedge.net https://edgecdn-embza6g8cacagcbn.z01.azurefd.net https://edgecdn-embza6g8cacagcbn.b02.azurefd.net;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
camera=(self), display-capture=(), fullscreen=(self), geolocation=(), microphone=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Strengthen CSP by removing 'unsafe-eval'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
187 domains
microsoftedge.com
blog.microsoftedge.com
bugs.microsoftedge.com
changelog.microsoftedge.com
data.microsoftedge.com
dev.microsoftedge.com
issues.microsoftedge.com
status.microsoftedge.com
testdrive.microsoftedge.com
www.microsoftedge.com
425show.dev
www.425show.dev
ambetion.be
www.ambetion.be
ambetion.digital
www.ambetion.digital
azurecontainerapp.com
azurecontainerapp.dev
azurecontainerapp.io
azurecontainerapp.net
azurecontainerapps.dev
azurecontainerapps.io
azurecosmosdb.com
blog.azuremaps.com
docs.azuremaps.com
updates.azuremaps.com
bellavite.org
bogdanss.com
businesscentral.dk
www.businesscentral.dk
cloudchampions11.com
archive.codeplex.com
codeplex.com
codeplex.net
codeplex.org
codeplex.ru
www.codeplex.ru
containers.dev
contextualiq.com
www.contextualiq.com
csshybrid.com
cssmigration.com
cupposunshine.com
d365iom.com
dallasdragon.com
www.dallasdragon.com
dallasdragon.org
www.dallasdragon.org
demoaccsm.com
digitalambetion.be
www.digitalambetion.be
digitalambetion.com
digitalambition.be
www.digitalambition.be
blog.dot.net
blogs.dot.net
dotnetpodcasts.com
dugodaj.com
www.dugodaj.com
dynamics.com
eenvoudig.nu
www.eenvoudig.nu
exchangehybrid.com
exchangehybrid.in
fluentui.dev
www.fluentui.dev
gears.gg
www.gears.gg
gears5.com
www.gears5.com
live.gearsofwar.com
gearspop.com
www.gearspop.com
gearstactics.com
www.gearstactics.com
gigjam.com
www.gigjam.com
gotcosmos.com
hololens.com
www.hololens.com
imaginecup.pl
www.imaginecup.pl
explore.live.com
maquette.ms
www.maquette.ms
mhybrid.cz
microsoft.az
microsoft.be
microsoft.by
microsoft.ca
www.microsoft.ca
microsoft.cat
microsoft.ch
microsoft.cl
microsoft.cz
www.microsoft.cz
microsoft.dk
microsoft.ee
microsoft.es
microsoft.eu
www.microsoft.eu
microsoft.fi
microsoft.ge
microsoft.hu
microsoft.is
microsoft.it
www.microsoft.it
microsoft.jp
www.microsoft.jp
microsoft.lt
microsoft.lu
microsoft.lv
microsoft.md
microsoft.pl
www.microsoft.pl
microsoft.pt
microsoft.ro
microsoft.rs
microsoft.ru
www.microsoft.ru
microsoft.se
microsoft.si
microsoft.tv
microsoft.ua
microsoft.uz
microsoft.vn
microsoftcloud.com
www.microsoftcloud.com
microsoftfederal.com
microsoftgamedev.com
mmynte.es
www.mmynte.es
mnc.ms
www.mnc.ms
feedback.msdn.com
msdn.com
www.msdn.com
msftgamedev.com
www.msftgamedev.com
msftgamedeveloper.com
msgamedev.com
www.msgamedev.com
msgamedev.net
www.msgamedev.net
msgamedev.org
www.msgamedev.org
msgamedeveloper.com
msgamedevelopment.com
nuget.ms
www.nuget.ms
olxwiki.com
www.olxwiki.com
www.pandoralabs.pt
qir-alliance.com
qir-alliance.org
qiralliance.com
qiralliance.org
ratify.sh
www.remix3d.com
rnmst1.com
skype.tv
www.skype.tv
myservice.surface.com
surface.com
www.surface.com
surfacepreskoly.sk
toycorp.org
typescriptlang.org
vanguardoutrider.com
vivaonboardingapp.dev
hardwaredev.windows.com
it.windows.com
itpro.windows.com
windows.com
www.windows.com
windows.nl
www.windows.nl
windowscontinuum.com
windowsmarketplace.com
www.windowsmarketplace.com
windowsuglysweater.com
winhec.com
www.winhec.com
winhec.net
www.winhec.net
myservice.xbox.com
xbox.com
Other domains in certificate