vercel.app
Scanned 8 days ago · Aug 11, 2026, 9:17 PM
A+
TLS & Certificate
Protocol support, cipher strength and the certificate chain, evaluated the way a browser would.
Score100%
NegotiatedTLSv1.3, TLS_AES_128_GCM_SHA256
Forward secrecyYes
HSTSenabled, max-age=63072000
Protocol support
YesTLS 1.3
YesTLS 1.2
NoTLS 1.1 (deprecated)
NoTLS 1.0 (deprecated)
Cipher suites probed
Each suite below was tested with its own TLS 1.2 handshake, restricted to exactly that cipher - “accepted” means the server completed a handshake using it, not merely that it's listed as a possibility.
ECDHE-ECDSA-AES256-GCM-SHA384
SecureNot offered
ECDHE-RSA-AES256-GCM-SHA384
SecureAccepted
ECDHE-ECDSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES128-GCM-SHA256
SecureAccepted
ECDHE-ECDSA-CHACHA20-POLY1305
SecureNot offered
ECDHE-RSA-CHACHA20-POLY1305
SecureAccepted
DHE-RSA-AES256-GCM-SHA384
SecureNot offered
DHE-RSA-AES128-GCM-SHA256
SecureNot offered
ECDHE-RSA-AES256-SHA384
WeakNot offered
ECDHE-RSA-AES128-SHA256
WeakNot offered
AES256-GCM-SHA384
WeakNot offered
AES128-GCM-SHA256
WeakNot offered
DES-CBC3-SHA
InsecureNot offered
RC4-SHA
InsecureNot offered
NULL-SHA
InsecureNot offered
Certificate
Subject*.vercel.app
IssuerWR1
Additional names*.vercel.app, vercel.app
ValidJun 27, 2026, 11:19 PM – Sep 25, 2026, 11:19 PM (expires in 45 days)
KeyRSA 2048 bit
Certificate chain3 certificate(s)
Trusted by common trust storesYes
Matches the scanned hostnameYes
Self-signedNo
C
Security Headers
The HTTP response headers browsers use to restrict what a page - or an attacker inside it - can do.
Score55%
- no Permissions-Policy header
- no Cross-Origin-Opener-Policy header
- no Cross-Origin-Resource-Policy header
- the Server header discloses "Vercel"
- the X-Powered-By header discloses "Next.js, Payload"
- cookie "_v-consent" is missing the HttpOnly flag
- cookie "_v-anonymous-id" is missing the HttpOnly flag
- cookie "_v-anonymous-id-renewed" is missing the HttpOnly flag
Content-Security-Policydefault-src 'self' vercel.com *.vercel.com assets.vercel.com *.vercel.sh vercel.live wss://*.vercel.com *.codesandbox.io localhost:* chrome-extension://* https://www.youtube-nocookie.com https://risk.clearbit.com https://react-tweet.vercel.app/*;script-src 'self' 'unsafe-eval' 'unsafe-inline' 'inline-speculation-rules' https://snap.licdn.com https://www.youtube.com cdn.vercel-insights.com va.vercel-scripts.com vercel.com *.vercel.com assets.vercel.com *.vercel.sh vercel.live wss://*.vercel.com *.codesandbox.io localhost:* chrome-extension://* https://www.youtube-nocookie.com https://risk.clearbit.com https://react-tweet.vercel.app/* cdp.vercel.com;style-src 'self' 'unsafe-inline' vercel.com *.vercel.com assets.vercel.com *.vercel.sh vercel.live wss://*.vercel.com *.codesandbox.io localhost:* chrome-extension://* https://www.youtube-nocookie.com https://risk.clearbit.com https://react-tweet.vercel.app/*;img-src 'self' blob: data: *.github.io avatars.githubusercontent.com user-images.githubusercontent.com vercel.com vercel.live *.vercel.sh assets.vercel.com cdn.raster.app https://images.ctfassets.net https://www.google.com https://i.ytimg.com https://s3.amazonaws.com pbs.twimg.com https://www.gravatar.com https://lishhsx6kmthaacj.public.blob.vercel-storage.com https://fvqcrhkhgatlyl2m.public.blob.vercel-storage.com;media-src 'self' blob: data: vercel.com *.vercel.com assets.vercel.com *.vercel.sh vercel.live wss://*.vercel.com *.codesandbox.io localhost:* chrome-extension://* https://www.youtube-nocookie.com https://risk.clearbit.com https://react-tweet.vercel.app/*;connect-src 'self' data: *.ingest.sentry.io *.ingest.us.sentry.io wss://ws-us3.pusher.com sockjs-use3.pusher.com react-tweet.vercel.app https://*.contentful.com www.vercel-status.com unpkg.com vercel.com *.vercel.com assets.vercel.com *.vercel.sh vercel.live wss://*.vercel.com *.codesandbox.io localhost:* chrome-extension://* https://www.youtube-nocookie.com https://risk.clearbit.com https://react-tweet.vercel.app/* cdp.vercel.com;font-src 'self' vercel.com assets.vercel.com vercel.live fonts.gstatic.com *.vercel.sh;frame-ancestors 'self' https://vercel.com https://app.contentful.com https://*.contentful.com https://*.vercel.sh https://*.vercel.com
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preload
X-Content-Type-Optionsnosniff
X-Frame-OptionsDENY
Referrer-Policyorigin-when-cross-origin
Permissions-Policynot set
Cross-Origin-Opener-Policynot set
Cross-Origin-Resource-Policynot set
Cookies_v-consent (Secure); _v-anonymous-id (Secure); _v-anonymous-id-renewed (Secure)
–Email
Whether mail delivered to this domain is protected in transit, and whether SPF/DMARC stop it being spoofed.
Scoren/a
- no mail servers (MX records) found for this domain