openai.com
Scanned 8 days ago · Aug 11, 2026, 9:21 PM
A+
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
Score100%
NegotiatedTLSv1.3, TLS_AES_256_GCM_SHA384
Forward secrecyYes
HSTSenabled, max-age=31536000
Protocol support
YesTLS 1.3
YesTLS 1.2
NoTLS 1.1 (deprecated)
NoTLS 1.0 (deprecated)
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - “accepted” means the server completed a handshake using it, not merely that it's listed as a possibility.
ECDHE-ECDSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureAccepted
ECDHE-RSA-CHACHA20-POLY1305
SecureAccepted
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakNot offered
ECDHE-RSA-AES128-SHA256
WeakNot offered
AES256-GCM-SHA384
WeakNot offered
AES128-GCM-SHA256
WeakNot offered
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered
Certificate
Subjectopenai.com
IssuerYE2
Additional names*.email.openai.com, openai.com
ValidAug 11, 2026, 3:16 AM – Nov 9, 2026, 3:16 AM (expires in 89 days)
KeyEC prime256v1
Certificate chain5 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
B
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
Score75%
- no Content-Security-Policy header
- the Server header discloses "cloudflare"
Content-Security-Policynot set
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preload
X-Content-Type-Optionsnosniff
X-Frame-OptionsSAMEORIGIN
Referrer-Policysame-origin
Permissions-Policyaccelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Cross-Origin-Opener-Policysame-origin
Cross-Origin-Resource-Policysame-origin
Cookies__cf_bm (Secure, HttpOnly)
A+Email
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
Score100%
- port 25 was not reachable on any mail server from our scanner (commonly blocked by cloud providers) - mail transport security could not be verified
SPFv=spf1 include:_spf.google.com include:spf.protection.outlook.com include:8050860.spf04.hubspotemail.net include:mktomail.com include:spf_c.oraclecloud.com -all
DMARCv=DMARC1; p=reject; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1; aspf=r
Mail servers
aspmx.l.google.comnot reachable on port 25 from our scanner
alt1.aspmx.l.google.comnot reachable on port 25 from our scanner
alt2.aspmx.l.google.comnot reachable on port 25 from our scanner