Open
Cached
·
just now
89/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=microsoft.com
Issuer
C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 07
Valid From
December 08, 2025
Valid Until
June 06, 2026
160 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA384-RSA
SHA-256 Fingerprint
30:3B:FD:C2:48:EA:9C:D4:BD:F9:3A:9A:E0:AA:6F:8E:EA:B2:9B:5C:98:60:FF:6D:99:D1:B4:10:9A:A2:1A:A0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15768000 ; includeSubDomains ; preload
Content-Security-Policy
Basic
script-src
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Not Authorized
(Potential misconfiguration)
Incident Reporting
mailto:[email protected]
CAA Issues
- • CRITICAL: Current certificate issuer 'C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 07' is NOT authorized by CAA records. Authorized CAs:
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
Subject Alternative Names
173 domains
vscode-edu.com
www.vscode-edu.com
2010office.it
www.2010office.it
adatum.ai
www.adatum.ai
aielectionsaccord.com
www.aielectionsaccord.com
www.applyxboxcreditcard.com
friday.azure.com
demo.azuremaps.com
bestxboxgames.com
www.bestxboxgames.com
book.ms
www.book.ms
boulder-innovations.com
www.boulder-innovations.com
copilotsi.com
www.copilotsi.com
docx.new
www.docx.new
excel.new
www.excel.new
exploresurface.com
www.exploresurface.com
auth.flip.com
help.flip.com
info.flip.com
forzamotorsport.net
rewards.forzamotorsport.net
www.forzamotorsport.net
shop.gearsofwar.com
getlicensingready.com
www.getlicensingready.com
www.getxboxcreditcard.com
www.gh.io
insightstomorrow.com
www.insightstomorrow.com
lakeshore-retail.com
www.lakeshore-retail.com
www.learnxboxcreditcard.com
dev.lobe.ai
www.lobe.ai
login.microsoft
m365copilot.com
www.m365copilot.com
m365telemetry.net
www.m365telemetry.net
makeitgreat.com.au
www.makeitgreat.com.au
airlift.microsoft.com
customers.microsoft.com
microsoft.com
microsoftcopilotstudio.microsoft.com
mybuild.microsoft.com
nonprofitcommunity.microsoft.com
onegdc.microsoft.com
powerusers-staging.microsoft.com
powerusers.microsoft.com
threatintel.microsoft.com
trials.transform.microsoft.com
ux.microsoft.com
ux.uat.microsoft.com
microsoft365copilot.com
microsoftintegrity.com
www.microsoftintegrity.com
microsoftoffice.help
www.microsoftoffice.help
microsoftsolitairecollection.com
www.microsoftsolitairecollection.com
mihsydney.com
www.mihsydney.com
minecraftdungeons.com
www.minecraftdungeons.com
minecrafteducation.net
www.minecrafteducation.net
msthreatintelpodcast.com
www.msthreatintelpodcast.com
new-office.it
www.new-office.it
nuovo-office.it
www.nuovo-office.it
o36ssupport.com
office-2013.it
www.office-2013.it
apc.delve.office.com
can.delve.office.com
delve-gcc.office.com
delve.office.com
df.delve.office.com
eur.delve.office.com
gbr.delve.office.com
gcc.delve.office.com
lam.delve.office.com
msit.delve.office.com
nam.delve.office.com
sfeur.delve.office.com
sfnam.delve.office.com
teamsdemo.office.com
office.download
www.office.download
office.email
www.office.email
office.live
www.office.live
office.microsoft
www.office.microsoft
office.security
www.office.security
office.support
www.office.support
office365-lavoro.it
www.office365-lavoro.it
office365proskoly.cz
www.office365proskoly.cz
office365support.ms
office365support.us
outlook-2013.it
www.outlook-2013.it
outlook2013.it
playxbox.com
www.playxbox.com
powerfuldevs.com
powerpoint.com
www.powerpoint.com
powerpoint.new
www.powerpoint.new
ppt.new
www.ppt.new
pptx.new
www.pptx.new
reflect.new
reflect.space
rnicrosoftsupport.com
scottandmarklearn.to
www.scottandmarklearn.to
scottandmarklearnto.com
www.scottandmarklearnto.com
www.thexboxcard.com
thexboxcreditcard.com
www.thexboxcreditcard.com
collectors.tivan.ms
forums.towerborne.com
www.forums.towerborne.com
trym365.com
www.trym365.com
visualstudio.blog
www.visualstudio.blog
vscode.education
www.vscode.education
winterstarfall.com
www.winterstarfall.com
word.new
www.word.new
www.office
www.xboxcreditcard.com
www.xboxdesignlab.com
xboxdesignlab.com
www.xboxgamer.com
xboxgamer.com
www.xboxgames.com
xboxgames.com
www.xboxgaming.com
xboxgaming.com
www.xboxplace.com
xboxplace.com
www.xboxplay.com
xboxplay.com
www.xboxrewardscard.com
www.xboxstar.com
xboxstar.com
www.xboxuserresearch.com
xboxuserresearch.com
Other domains in certificate