example.com
Scanned 8 days ago · Aug 11, 2026, 9:16 PM
A-
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
Score80%
- the server accepts 4 weak cipher suite(s): ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-SHA256, AES256-GCM-SHA384, AES128-GCM-SHA256
- no Strict-Transport-Security (HSTS) header
NegotiatedTLSv1.3, TLS_AES_256_GCM_SHA384
Forward secrecyYes
HSTSnot enabled
Protocol support
YesTLS 1.3
YesTLS 1.2
NoTLS 1.1 (deprecated)
NoTLS 1.0 (deprecated)
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - “accepted” means the server completed a handshake using it, not merely that it's listed as a possibility.
ECDHE-ECDSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureAccepted
ECDHE-RSA-CHACHA20-POLY1305
SecureAccepted
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakAccepted
ECDHE-RSA-AES128-SHA256
WeakAccepted
AES256-GCM-SHA384
WeakAccepted
AES128-GCM-SHA256
WeakAccepted
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered
Certificate
Subjectexample.com
IssuerCloudflare TLS Issuing ECC CA 3
Additional namesexample.com, *.example.com
ValidJul 29, 2026, 10:10 PM – Oct 27, 2026, 10:17 PM (expires in 77 days)
KeyEC prime256v1
Certificate chain4 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
F
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
Score10%
- no Content-Security-Policy header
- no Strict-Transport-Security header
- no X-Content-Type-Options: nosniff
- no clickjacking protection (X-Frame-Options or frame-ancestors)
- no Referrer-Policy header
- no Permissions-Policy header
- no Cross-Origin-Opener-Policy header
- no Cross-Origin-Resource-Policy header
- the Server header discloses "cloudflare"
Content-Security-Policynot set
Strict-Transport-Securitynot set
X-Content-Type-Optionsnot set
X-Frame-Optionsnot set
Referrer-Policynot set
Permissions-Policynot set
Cross-Origin-Opener-Policynot set
Cross-Origin-Resource-Policynot set
–Email
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
Scoren/a
- no mail servers (MX records) found for this domain