SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Hostname Mismatch - certificate is issued for www.iphone.rio, livephotos.rio, appletv.rio, www.itunesstore.rio, ipod.rio, www.applestore.rio, macbook.rio, www.applewatch.rio, itunesstore.rio, not for www.wwwitunes.com
Open
Cached
·
10h ago
71/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=California, O=Apple Inc., CN=appleid.rio
Issuer
C=US, O=Apple Inc., CN=Apple Public Server RSA CA 1 - G1
Valid From
February 16, 2026
Valid Until
May 17, 2026
21 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E8:47:4B:5E:7E:1F:27:9F:33:0E:B9:62:2D:72:8D:93:B4:50:75:78:08:86:D8:27:D6:17:CE:C7:69:D4:F4:BF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Not Authorized
(Potential misconfiguration)
Authorized CAs
Wildcard CAs
Incident Reporting
mailto:[email protected]
CAA Issues
- • CRITICAL: Current certificate issuer 'C=US, O=Apple Inc., CN=Apple Public Server RSA CA 1 - G1' is NOT authorized by CAA records. Authorized CAs: pki.apple.com
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
Subject Alternative Names
44 domains
appleid.rio
www.appleid.rio
applelivephotos.rio
www.applelivephotos.rio
applemusic.rio
applemusicfestival.rio
applenews.rio
applepay.rio
applestore.rio
www.applestore.rio
appletv.rio
www.appletv.rio
applewatch.rio
www.applewatch.rio
appstore.rio
beats1.rio
beats2.rio
beats3.rio
beats4.rio
beats5.rio
icloud.rio
www.icloud.rio
ipad.rio
www.ipad.rio
ipadpro.rio
www.ipadpro.rio
iphone.rio
www.iphone.rio
ipod.rio
www.ipod.rio
itunes.rio
www.itunes.rio
itunesradio.rio
www.itunesradio.rio
itunesstore.rio
www.itunesstore.rio
livephotos.rio
www.livephotos.rio
mac.rio
www.mac.rio
macbook.rio
www.macbook.rio
macstore.rio
www.macstore.rio