HTTPS Readiness test

Input

Check here if your site complies with the HTTPS best practices

Domain analysis: www.yahoo.com

  • Always redirect to same domain https://www.yahoo.com (BEST PRACTICE!)
  • IP addresses: 87.248.100.215, 87.248.100.216
  • Certificate details

  • This SSL Certificate was created for yahoo.com and is also valid for subdomain www.yahoo.com
  • Certificate issued by DigiCert Inc, of type DigiCert SHA2 High Assurance Server CA
  • Certificate start date: Jul 12 00:00:00 2022 GMT
  • Certificate expiration: Jan 4 23:59:59 2023 GMT (in 147 days)
  • Certificate validity period: 177 days (probably automated renewal)
  • Encryption algorithm: TLSv1.3 / TLS_AES_128_GCM_SHA256
  • More certificate details?
  • SSL Labs: get more detailed HTTPS report
  • Mozilla Observatory: get more detailed HTTPS report
  • HTTPS Headers

  • Missing HTTP header x-frame-options - should be SAMEORIGIN
  • HTTP header content-security-policy is wrong - not a valid format - please check
    sandbox allow-forms allow-same-origin allow-scripts allow-popups allow-popups-to-escape-sandbox allow-presentation; report-uri https://csp.yahoo.com/beacon/csp?src=ats&site=frontpage®ion=US&lang=en-US&device=desktop&yrid=7su7crhhf7fmp&partner=; frame-ancestors 'self' https://*.techcrunch.com https://*.yahoo.com https://*.aol.com https://*.huffingtonpost.com https://*.oath.com https://*.search.yahoo.com https://*.search.aol.com https://*.search.huffpost.com htts://*.verizonmedia.com https://*.publishing.oath.com
  • HTTP header x-xss-protection is OK - cross-scripting protection
  • HTTP header strict-transport-security (HSTS) is OK (12 months valid)
  • For a GDPR-focused review of your domain, use Churlie GDPR Checkup
  • Content details

  • Mixed content: this page uses insecure content from csp.yahoo.com
  • How to get https for your site

    References