Open Cached · just now
70/100 SECURITY SCORE

Certificate Information

Subject
C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.work.alibabacorp.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign GCC R3 OV TLS CA 2024
Valid From
June 23, 2025
Valid Until
July 25, 2026 252 days
Public Key
ECDSA 256 bit (P-256) Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
11:2C:42:0A:A8:18:80:61:4D:67:F6:81:C8:30:89:F6:6C:2C:C3:32:81:90:A5:3E:5C:51:5B:33:5B:31:6B:BC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.0 TLS 1.1 TLS 1.2
Forward Secrecy
Limited (Check cipher configuration)
Warnings
  • TLS 1.3 is not supported (recommended)
  • TLS 1.1 is deprecated and should be disabled
  • TLS 1.0 is deprecated and should be disabled

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

447 domains
*.sm.cn *.data.sm.cn *.m.sm.cn *.rs.sm.cn *.sm-hadoop.sm.cn

Other domains in certificate

*.11222.cn
*.25pp.com *.sjzs-api.25pp.com
*.56xiniao.com
9game.cn *.admin.9game.cn *.assistant.9game.cn *.client.9game.cn *.data.9game.cn *.gh.9game.cn *.guild.9game.cn *.huiyuan.9game.cn *.sdk.9game.cn *.sdkyy.9game.cn *.static.9game.cn *.web.9game.cn
*.abird.alibaba-inc.com *.aclchecking.alibaba-inc.com *.adc.alibaba-inc.com *.admin.report.alibaba-inc.com *.adstl.alibaba-inc.com *.ailabs.alibaba-inc.com *.airec.alibaba-inc.com *.ais.alibaba-inc.com *.alibaba-inc.com.alibaba-inc.com *.alidrill.alibaba-inc.com *.alios.alibaba-inc.com *.alphamatte.alibaba-inc.com *.alsc.alibaba-inc.com *.aop-service.alibaba-inc.com *.aop.alibaba-inc.com *.ap-southeast-1.alibaba-inc.com *.api-portal.alibaba-inc.com api.nightwatch.alibaba-inc.com *.appstudio.alibaba-inc.com *.appupgrade.alibaba-inc.com *.ark-helper.alibaba-inc.com *.asi.alibaba-inc.com *.ats.alibaba-inc.com *.autolabel.alibaba-inc.com *.awp.alibaba-inc.com *.caijing.alibaba-inc.com *.cayman.alibaba-inc.com *.cdr.alibaba-inc.com *.center.alibaba-inc.com *.cluster.alibaba-inc.com *.cn-shenzhen.alibaba-inc.com *.codeworks.alibaba-inc.com *.copyright.alibaba-inc.com *.cpp.alibaba-inc.com *.crc.alibaba-inc.com *.crocodile.alibaba-inc.com *.damo.alibaba-inc.com *.daraz.alibaba-inc.com *.data.alibaba-inc.com *.db.alibaba-inc.com *.dcos.alibaba-inc.com *.decoration.alibaba-inc.com *.deploy.sigma.alibaba-inc.com *.df.alibaba-inc.com *.dg.alibaba-inc.com *.dingtalk.alibaba-inc.com *.doa.alibaba-inc.com *.droplet.alibaba-inc.com *.dvs.alibaba-inc.com *.ec.alibaba-inc.com *.ecs.alibaba-inc.com *.ele.alibaba-inc.com *.elesearch.alibaba-inc.com *.eng.alibaba-inc.com *.eps.alibaba-inc.com *.esdb.alibaba-inc.com *.euler.alibaba-inc.com *.f11.alibaba-inc.com *.fbi.alibaba-inc.com *.fe.alibaba-inc.com *.fun.alibaba-inc.com *.fusion.alibaba-inc.com *.fuxi.alibaba-inc.com *.g.alibaba-inc.com *.game.alibaba-inc.com *.gi.alibaba-inc.com *.grep.alibaba-inc.com *.ha.emas.alibaba-inc.com *.ha3.alibaba-inc.com *.hermes.alibaba-inc.com *.hippod.alibaba-inc.com *.hooma.alibaba-inc.com *.imgtech-demo.alibaba-inc.com *.inner.alibaba-inc.com *.insight.alibaba-inc.com *.internal.alibaba-inc.com *.jupyter.alibaba-inc.com *.kbalgo.alibaba-inc.com *.kcloud.alibaba-inc.com *.keeper.alibaba-inc.com *.klj.alibaba-inc.com *.koubei.alibaba-inc.com *.kunlun.alibaba-inc.com *.lancet.alibaba-inc.com *.ledongli.alibaba-inc.com *.louvre.alibaba-inc.com *.lsp.alibaba-inc.com *.ltp.alibaba-inc.com *.lzdchat.alibaba-inc.com *.mit.alibaba-inc.com *.mozi.alibaba-inc.com *.mtl4.alibaba-inc.com *.muchenzhu.alibaba-inc.com *.mys.alibaba-inc.com *.netseer2-controller.alibaba-inc.com *.newretail.pick.admin.ele.alibaba-inc.com *.newretail.putin.admin.ele.alibaba-inc.com *.newultron.alibaba-inc.com *.ngw.alibaba-inc.com *.nls-aim-console.alibaba-inc.com *.nls.alibaba-inc.com *.now.alibaba-inc.com *.o2o.alibaba-inc.com *.odps.alibaba-inc.com *.og.alibaba-inc.com *.oneapp.alibaba-inc.com *.online.alibaba-inc.com *.oops.alibaba-inc.com *.oops2.alibaba-inc.com *.open.alibaba-inc.com *.pagetest.alibaba-inc.com *.pai-admin.alibaba-inc.com *.parrot.alibaba-inc.com *.party.alibaba-inc.com *.pcs.alibaba-inc.com *.pilot.alibaba-inc.com *.pora.alibaba-inc.com *.porsche.alibaba-inc.com *.pouch-ops.alibaba-inc.com *.pouch.alibaba-inc.com *.pre-appstudio.alibaba-inc.com *.pre-caijing.alibaba-inc.com *.pre-fbi.alibaba-inc.com pre-security.mibo.alibaba-inc.com *.pre-starship.alibaba-inc.com *.pre.alibaba-inc.com *.private-test.alibaba-inc.com *.proxy.alibaba-inc.com *.qin.alibaba-inc.com *.r-alicode.alibaba-inc.com *.r2-alicode.alibaba-inc.com *.rbc.alibaba-inc.com *.report.alibaba-inc.com *.ricciflow.alibaba-inc.com *.robotics.alibaba-inc.com *.ru.alibaba-inc.com *.runtime2-alicode.alibaba-inc.com *.ruyi.alibaba-inc.com *.santa-pro.alibaba-inc.com *.schecule.alibaba-inc.com *.schedulerx2.alibaba-inc.com *.secops.alibaba-inc.com *.security.data.alibaba-inc.com *.security.newton.alibaba-inc.com *.serverless.alibaba-inc.com *.sgunit.alibaba-inc.com *.shenma.alibaba-inc.com *.singlab.alibaba-inc.com *.skywalker.alibaba-inc.com *.slm.alibaba-inc.com *.sm.alibaba-inc.com *.smart-health.alibaba-inc.com *.smartdev.alibaba-inc.com *.solution.alibaba-inc.com *.span.alibaba-inc.com *.speedgear.alibaba-inc.com *.srp.alibaba-inc.com *.std-api-server.alibaba-inc.com *.sync.alibaba-inc.com *.sz.alibaba-inc.com *.t3d.alibaba-inc.com *.taopiaopiao.alibaba-inc.com *.tdw.alibaba-inc.com *.teambition.alibaba-inc.com *.tes-sg.alibaba-inc.com *.tesla.alibaba-inc.com *.test-appstudio.alibaba-inc.com *.test.alibaba-inc.com *.thead.alibaba-inc.com *.tianti.alibaba-inc.com *.tmallgenie.teambition.alibaba-inc.com *.tms.alibaba-inc.com *.tool.alibaba-inc.com *.torch.alibaba-inc.com *.tpp.alibaba-inc.com *.tppqa.alibaba-inc.com *.tsdb.alibaba-inc.com *.turing.alibaba-inc.com *.uae2-uc.alibaba-inc.com *.uc.alibaba-inc.com *.ultron.alibaba-inc.com *.umbrella.alibaba-inc.com *.union.alibaba-inc.com *.uop.alibaba-inc.com *.us.alibaba-inc.com video.scs.alibaba-inc.com *.vipserver.alibaba-inc.com *.wakanda.alibaba-inc.com *.xdata.alibaba-inc.com *.xide.alibaba-inc.com *.xlab.alibaba-inc.com *.xnet2-configcenter.alibaba-inc.com *.xnet3-model.alibaba-inc.com *.xtest.alibaba-inc.com *.xtop.alibaba-inc.com *.youku-data-camp.alibaba-inc.com *.yt.alibaba-inc.com *.zootopia2.alibaba-inc.com
*.china.alibaba.cn
work.alibabacorp.com *.work.alibabacorp.com
*.alibabadesign.com
*.alibabapictures.com
*.alibabausercontent.com
*.assets.alicdn.com *.g.alicdn.com
alifanyi.com
aligenie.com *.aligenie.com *.m.aligenie.com
*.witmed.alihealth.cn
aliimg.com *.aliimg.com *.c.aliimg.com
*.api.alimama.com *.avengers.alimama.com *.daily.alimama.com *.dnn-test.alimama.com *.dnn.alimama.com *.effect.alimama.com *.feedback.alimama.com *.ml.alimama.com *.themis.alimama.com *.uc.alimama.com *.ucontent.alimama.com *.union.alimama.com *.usermatch.alimama.com *.wireless.alimama.com
*.aliplay.com
*.open.aliplus.com
*.flyproxy.alitrip.com *.sell.alitrip.com
aliunicorn.com
*.aliwx.net
alixiaomi.com
*.abs.amap.com *.api.amap.com *.asbp.amap.com *.auditpeg.amap.com *.autoeddapistore.amap.com *.autolr.amap.com *.boss.amap.com *.chuxing.amap.com *.et-api.amap.com *.evaluate.amap.com *.falcon.amap.com *.finance.amap.com *.ggc.amap.com *.innovation.amap.com *.lbs.amap.com *.office.amap.com *.poi.amap.com *.pre-test.amap.com *.pre.amap.com *.prepub.amap.com *.proxy.amap.com *.publish.amap.com *.push.amap.com *.restapi.amap.com *.test.amap.com *.tianqi.amap.com *.vdata.amap.com *.work.amap.com *.xn.amap.com
amapauto.com *.amapauto.com
*.admin0.atatech.org
*.auto.cainiao-inc.com *.cloud.cainiao-inc.com *.cncv.cainiao-inc.com *.eaglet.cainiao-inc.com *.global.cainiao-inc.com *.park.cainiao-inc.com *.pre.cainiao-inc.com *.proxy.cainiao-inc.com *.test.cainiao-inc.com *.toffee.cainiao-inc.com *.vision.cainiao-inc.com
*.ai.cainiao.com *.auto.cainiao.com *.coll.cainiao.com *.crm.xpm.cainiao.com *.edi-pre.xpm.cainiao.com *.etlab.cainiao.com *.eye.cainiao.com *.gos.cainiao.com *.gwms.cainiao.com *.imp.cainiao.com *.jenkins.cainiao.com *.mcs.xpm.cainiao.com *.planning.data.dms.cainiao.com *.presssure.cainiao.com *.tmsx.cainiao.com *.was.cainiao.com *.wmp.cainiao.com *.xpm.cainiao.com *.yc.cainiao.com
*.admin.alihealth.com.cn *.aliwx.com.cn
*.coolact.net
*.dailyact.cn
*.2019fbwc.damai.cn *.api.damai.cn *.cfs.damai.cn *.en.damai.cn *.jp.damai.cn *.m.damai.cn *.pj.damai.cn *.platform.damai.cn *.seat.damai.cn *.trade.damai.cn
*.business.danniao.com *.danniao.com *.dingtalk.danniao.com *.hr.danniao.com *.mcs.danniao.com
*.open.dayu.com
*.club.dingtalk.com *.hammer.dingtalk.com *.open-dev.dingtalk.com *.pre-open-dev.dingtalk.com *.scope.dingtalk.com *.ww.dingtalk.com
*.dotwe.org
*.duanqu.com *.ut.duanqu.com
e22a.com m.e22a.com www.e22a.com
*.buy.fliggy.com *.carts2.fliggy.com *.flight.fliggy.com *.fm.fliggy.com *.pre-tcgw.fliggy.com *.sell.fliggy.com
*.flysdk.cn
*.flyzoohotel.com
*.fusion.design
*.agent.hemaos.com *.hemaos.comrights.hemaos.com *.invoice.hemaos.com *.market.hemaos.com *.pre-umstest.hemaos.com *.rexmedia.hemaos.com *.scm-allocate.hemaos.com *.scm-purchase.hemaos.com *.scm-transfer.hemaos.com *.search.hemaos.com *.ums.hemaos.com *.unity.hemaos.com *.wdk-launch.hemaos.com
iconfont.cn
*.ishuqi.com
*.jiaoyimao.cn *.pl.jiaoyimao.cn *.super.jiaoyimao.cn
jiaoyimao.com
v.mashort.cn
*.mypiao.com *.wx.mypiao.com
*.newstjk.com
open-uc.cn *.open-uc.cn
*.piao.cn
*.activity.pp.cn *.api.pp.cn *.cs.pp.cn *.m.pp.cn *.pp.cn
*.pullnew.cn
*.rantu.com
*.rexpos.cn
*.rextech.cn
*.shejijia.com
shuqi.com *.shuqi.com *.static.shuqi.com
*.shuqiapi.com
*.shuqiread.com
*.api.shuqireader.com
*.sqreader.com *.tmreader.sqreader.com
t-head.cn *.t-head.cn
*.alimm.taobao.org *.alireader.taobao.org *.bach.taobao.org *.boot.taobao.org *.dop.taobao.org *.gallery.taobao.org *.gpu1094.taobao.org *.kcloud.taobao.org *.kclub.taobao.org *.ops.taobao.org *.tmobile.taobao.org *.ucontent.taobao.org *.yingxianproxy.taobao.org
*.taopiaopiao.cn
tb.cn
*.tjnewsk.com
*.ucgc.ucfly.com
*.uflowx.com
*.finplus.umeng.com *.mob.umeng.com *.www.umeng.com
*.api.wandoujia.com *.wandoujia.com
*.wesg.com
*.content.xiami.com
*.stage.xpmeng.com *.xpmeng.com
xunxi.com *.xunxi.com
yousuode.cn
*.open.yuekeyun.com *.yuekeyun.com
*.video.yunos-inc.com
*.alitv.yunos.com apnsproxy.rtmp.yunos.com *.cm.yunos.com *.ra.yunos.com *.search.yunos.com *.tv.yunos.com *.video.yunos.com
*.yunshangzhipian.com
*.reportmeta.yushanfang.com