cloudflare.com

Scanned 8 days ago · Aug 11, 2026, 9:17 PM

A

TLS & Certificate

Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.

Score90%
  • the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
NegotiatedTLSv1.3, TLS_AES_256_GCM_SHA384
Forward secrecyYes
HSTSenabled, max-age=15780000

Protocol support

YesTLS 1.3
YesTLS 1.2
NoTLS 1.1 (deprecated)
NoTLS 1.0 (deprecated)

Cipher suites probed

Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - “accepted” means the server completed a handshake using it, not merely that it's listed as a possibility.

ECDHE-ECDSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureAccepted
ECDHE-RSA-CHACHA20-POLY1305
SecureAccepted
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakAccepted
ECDHE-RSA-AES128-SHA256
WeakAccepted
AES256-GCM-SHA384
WeakAccepted
AES128-GCM-SHA256
WeakAccepted
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered

Certificate

Subjectcloudflare.com
IssuerWE1
Additional namescloudflare.com, ns.cloudflare.com, *.ns.cloudflare.com, *.secondary.cloudflare.com, secondary.cloudflare.com
ValidJul 8, 2026, 9:47 PM – Oct 6, 2026, 10:47 PM (expires in 56 days)
KeyEC prime256v1
Certificate chain3 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
A

Security Headers

The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.

Score95%
  • the Server header discloses "cloudflare"
Content-Security-Policydefault-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.cloudflareinsights.com https://static-staging.cloudflareinsights.com https://challenges.cloudflare.com https://*.onetrust.com https://cdn.cookielaw.org https://ot.www.cloudflare.com https://www.googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://adservice.google.com https://cdn.bizible.com https://js.adsrvr.org https://*.marketo.net https://platform.twitter.com https://static.ads-twitter.com https://scripts.demandbase.com https://tag.demandbase.com https://*.6sc.co https://*.qualified.com https://snap.licdn.com https://bat.bing.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.doubleclick.net https://www.googleadservices.com https://translate.googleapis.com https://cdn.bizible.com https://js.adsrvr.org https://*.marketo.net https://ads-twitter.com https://analytics.twitter.com https://*.twimg.com https://api.demandbase.com https://scripts.demandbase.com https://tag.demandbase.com https://tag-logger.demandbase.com https://api.company-target.com https://*.6sc.co https://epsilon.6sense.com https://*.qualified.com wss://*.qualified.com https://*.ads.linkedin.com https://www.linkedin.com https://bat.bing.com https:; frame-src https://*.adsrvr.org https://*.cloudflare.com https://*.videodelivery.net https://*.cloudflarestream.com https://www.googletagmanager.com https://*.qualified.com https://td.doubleclick.net https://bid.g.doubleclick.net https://9309168.fls.doubleclick.net https://9973066.fls.doubleclick.net https://s.company-target.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; worker-src 'self' blob:; child-src 'self' blob:; upgrade-insecure-requests
Strict-Transport-Securitymax-age=31536000; includeSubDomains
X-Content-Type-Optionsnosniff
X-Frame-OptionsSAMEORIGIN
Referrer-Policystrict-origin-when-cross-origin
Permissions-Policygeolocation=(), camera=(), microphone=()
Cross-Origin-Opener-Policyunsafe-none
Cross-Origin-Resource-Policycross-origin
Cookies__cf_bm (Secure, HttpOnly)
A+

Email

Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.

Score100%
SPFv=spf1 ip4:199.15.212.0/22 ip4:173.245.48.0/20 include:_spf.google.com include:spf1.mcsv.net include:spf.mandrillapp.com include:mail.zendesk.com include:stspg-customer.com include:_spf.salesforce.com -all
DMARCv=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; pct=100; rua=mailto:[email protected],mailto:[email protected]

Mail servers

mxa-canary.global.inbound.cf-emailsecurity.netSTARTTLS, TLSv1.3
mxb-canary.global.inbound.cf-emailsecurity.netSTARTTLS, TLSv1.3
mxb.global.inbound.cf-emailsecurity.netSTARTTLS, TLSv1.3