Guest session
Check Detail

google.com · DNS

Passed Grade A
100.0%
Hostname google.com
Check name DNS
last run 11/11/2025 07:54
Result
Incomplete Grade B 76.9%

Result Detail

DNS
Host Type Answer TTL
142.250.185.142
2a00:1450:4001:810::200e

Result Detail

HEADER
Alerts
  • Strict-Transport-Security: Strict-Transport-Security missing
  • Content-Security-Policy: Content-Security-Policy missing
  • X-Content-Type-Options: Header missing
  • Referrer-Policy: Header missing
  • Cross-Origin-Opener-Policy: Unexpected value
  • Cross-Origin-Embedder-Policy: Header missing
  • Cross-Origin-Resource-Policy: Header missing
  • Expect-CT: Expect-CT missing
  • X-Permitted-Cross-Domain-Policies: Header missing
  • Access-Control-Allow-Origin: Access-Control-Allow-Origin missing
  • Server: Sensitive header exposed
  • Origin-Agent-Cluster: Header missing
Normalized headers
location https://www.google.com/
content-type text/html; charset=UTF-8
content-security-policy-report-only object-src 'none';base-uri 'self';script-src 'nonce-dFIf1xyBIO_AugYNHswsUA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp
cross-origin-opener-policy same-origin-allow-popups; report-to="gws"
report-to {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/other"}]}
permissions-policy unload=()
date Tue, 11 Nov 2025 06:54:19 GMT
expires Thu, 11 Dec 2025 06:54:19 GMT
cache-control public, max-age=2592000
server gws
content-length 220
x-xss-protection 0
x-frame-options SAMEORIGIN
alt-svc h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Transport
Check name Status Actual Expected Detail Severity Recommendation
Strict-Transport-Security ❌ Missing max-age>=15768000; includeSubDomains; preload Strict-Transport-Security missing Critical Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Expect-CT ❌ Missing enforce; max-age>=86400 Expect-CT missing Medium Expect-CT: enforce, max-age=86400, report-uri="https://report.example.com"
Content Security
Check name Status Actual Expected Detail Severity Recommendation
Content-Security-Policy ❌ Missing default-src 'self'; frame-ancestors 'none' Content-Security-Policy missing Critical Content-Security-Policy: default-src 'self'; frame-ancestors 'none'
MIME
Check name Status Actual Expected Detail Severity Recommendation
X-Content-Type-Options ❌ Missing nosniff Header missing High X-Content-Type-Options: nosniff
Framing
Check name Status Actual Expected Detail Severity Recommendation
X-Frame-Options ✅ Passed SAMEORIGIN DENY or SAMEORIGIN Value accepted High X-Frame-Options: DENY
Privacy
Check name Status Actual Expected Detail Severity Recommendation
Referrer-Policy ❌ Missing strict-origin-when-cross-origin / same-origin Header missing Medium Referrer-Policy: strict-origin-when-cross-origin
Browser Features
Check name Status Actual Expected Detail Severity Recommendation
Permissions-Policy ✅ Passed unload=() camera=(); geolocation=(); microphone=() camera=(); geolocation=(); microphone=() Medium Permissions-Policy: camera=(), geolocation=(), microphone=()
Cross-Origin
Check name Status Actual Expected Detail Severity Recommendation
Cross-Origin-Opener-Policy ❌ Missing same-origin-allow-popups; report-to="gws" same-origin Unexpected value High Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy ❌ Missing require-corp Header missing High Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Resource-Policy ❌ Missing same-origin Header missing Medium Cross-Origin-Resource-Policy: same-origin
Origin-Agent-Cluster ❌ Missing ?1 Header missing Low Origin-Agent-Cluster: ?1
Caching
Check name Status Actual Expected Detail Severity Recommendation
Cache-Control ✅ Passed public, max-age=2592000 no-store, private, max-age=0 no-store, private, max-age=0 High Cache-Control: no-store, private, max-age=0
Legacy
Check name Status Actual Expected Detail Severity Recommendation
X-Permitted-Cross-Domain-Policies ❌ Missing none Header missing Low X-Permitted-Cross-Domain-Policies: none
CORS
Check name Status Actual Expected Detail Severity Recommendation
Access-Control-Allow-Origin ❌ Missing Scoped origin (no wildcard) Access-Control-Allow-Origin missing Medium Access-Control-Allow-Origin: https://app.example.com
Information Disclosure
Check name Status Actual Expected Detail Severity Recommendation
Server ❌ Missing gws Header removed or generic Sensitive header exposed High Remove Server header or set to a generic token
X-Powered-By ✅ Passed Header removed Header not exposed High Remove X-Powered-By header
X-AspNet-Version ✅ Passed Header removed Header not exposed Medium Remove framework version headers
Raw headers
HTTP/2 301 
location: https://www.google.com/
content-type: text/html; charset=UTF-8
content-security-policy-report-only: object-src 'none';base-uri 'self';script-src 'nonce-dFIf1xyBIO_AugYNHswsUA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp
cross-origin-opener-policy: same-origin-allow-popups; report-to="gws"
report-to: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/other"}]}
permissions-policy: unload=()
date: Tue, 11 Nov 2025 06:54:19 GMT
expires: Thu, 11 Dec 2025 06:54:19 GMT
cache-control: public, max-age=2592000
server: gws
content-length: 220
x-xss-protection: 0
x-frame-options: SAMEORIGIN
alt-svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000

Result Detail

SSL
Check name Status Value
certificate chain is complete ✅ Passed 4
root CA is trusted ✅ Passed Trusted
cert valid for ✅ Passed 55
chain certs are valid until ✅ Passed 05.01.2026
CN matches Domainname ✅ Passed google.com
certificate subject ✅ Passed CN=*.google.com
certificate issuer ✅ Passed C=US, O=Google Trust Services, CN=WE2
signature algorithm ✅ Passed ecdsa-with-SHA256
TLS protocol ✅ Passed TLSv1.3 TLS_AES_256_GCM_SHA384
Subject Alternative Names ✅ Passed *.google.com, *.appengine.google.com, *.bdn.dev, *.origin-test.bdn.dev, *.cloud.google.com, *.crowdsource.google.com, *.datacompute.google.com, *.google.ca, *.google.cl, *.google.co.in, *.google.co.jp, *.google.co.uk, *.google.com.ar, *.google.com.au, *.google.com.br, *.google.com.co, *.google.com.mx, *.google.com.tr, *.google.com.vn, *.google.de, *.google.es, *.google.fr, *.google.hu, *.google.it, *.google.nl, *.google.pl, *.google.pt, *.googleapis.cn, *.googlevideo.com, *.gstatic.cn, *.gstatic-cn.com, googlecnapps.cn, *.googlecnapps.cn, googleapps-cn.com, *.googleapps-cn.com, gkecnapps.cn, *.gkecnapps.cn, googledownloads.cn, *.googledownloads.cn, recaptcha.net.cn, *.recaptcha.net.cn, recaptcha-cn.net, *.recaptcha-cn.net, widevine.cn, *.widevine.cn, ampproject.org.cn, *.ampproject.org.cn, ampproject.net.cn, *.ampproject.net.cn, google-analytics-cn.com, *.google-analytics-cn.com, googleadservices-cn.com, *.googleadservices-cn.com, googlevads-cn.com, *.googlevads-cn.com, googleapis-cn.com, *.googleapis-cn.com, googleoptimize-cn.com, *.googleoptimize-cn.com, doubleclick-cn.net, *.doubleclick-cn.net, *.fls.doubleclick-cn.net, *.g.doubleclick-cn.net, doubleclick.cn, *.doubleclick.cn, *.fls.doubleclick.cn, *.g.doubleclick.cn, dartsearch-cn.net, *.dartsearch-cn.net, googletraveladservices-cn.com, *.googletraveladservices-cn.com, googletagservices-cn.com, *.googletagservices-cn.com, googletagmanager-cn.com, *.googletagmanager-cn.com, googlesyndication-cn.com, *.googlesyndication-cn.com, *.safeframe.googlesyndication-cn.com, app-measurement-cn.com, *.app-measurement-cn.com, gvt1-cn.com, *.gvt1-cn.com, gvt2-cn.com, *.gvt2-cn.com, 2mdn-cn.net, *.2mdn-cn.net, googleflights-cn.net, *.googleflights-cn.net, admob-cn.com, *.admob-cn.com, *.gemini.cloud.google.com, googlesandbox-cn.com, *.googlesandbox-cn.com, *.safenup.googlesandbox-cn.com, *.gstatic.com, *.metric.gstatic.com, *.gvt1.com, *.gcpcdn.gvt1.com, *.gvt2.com, *.gcp.gvt2.com, *.url.google.com, *.youtube-nocookie.com, *.ytimg.com, ai.android, android.com, *.android.com, *.flash.android.com, g.cn, *.g.cn, g.co, *.g.co, goo.gl, www.goo.gl, google-analytics.com, *.google-analytics.com, google.com, googlecommerce.com, *.googlecommerce.com, ggpht.cn, *.ggpht.cn, urchin.com, *.urchin.com, youtu.be, youtube.com, *.youtube.com, music.youtube.com, *.music.youtube.com, youtubeeducation.com, *.youtubeeducation.com, youtubekids.com, *.youtubekids.com, yt.be, *.yt.be, android.clients.google.com, *.android.google.cn, *.chrome.google.cn, *.developers.google.cn, *.aistudio.google.com
Public Key ✅ Passed EC 256
Certificate chain
# Common name Issuer Valid until CA
0 *.google.com C=US, O=Google Trust Services, CN=WE2 05.01.2026 09:37:45 No
1 *.google.com C=US, O=Google Trust Services, CN=WE2 05.01.2026 09:37:45 No
2 WE2 C=US, O=Google Trust Services LLC, CN=GTS Root R4 20.02.2029 15:00:00 Yes
3 GTS Root R4 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA 28.01.2028 01:00:42 Yes
TLS details
Negotiated protocol TLSv1.3
Cipher suite TLS_AES_256_GCM_SHA384 (256 bit)
Cipher version TLSv1.3
Perfect Forward Secrecy Attention
Earliest chain expiry 05.01.2026 09:37
Fingerprints
SHA-256 DE:F5:87:79:4F:56:FB:34:64:B9:21:C9:8F:92:27:D5:ED:C7:A3:88:BD:53:84:65:7D:EF:99:09:59:84:48:BE
SHA-1 2C:0B:CF:F3:2B:F7:F0:76:D4:B1:1F:DB:E2:21:58:B5:EC:B7:6A:FF
Revocation
OCSP URLs
http://o.pki.goog/we2
CRL URLs
Full Name: URI:http://c.pki.goog/we2/xuzt3PU9F_w.crl
Issuer URLs (AIA)
http://i.pki.goog/we2.crt
OCSP Must-Staple No
Trust evaluation

Attempted: Yes

Trusted: Yes

OpenSSL diagnostic command
openssl s_client -connect google.com:443 -servername google.com

Result Detail

WAF
Sign up to use!
Ownership verification required

Real WAF results become available after signing up. Until then we show you a small teaser from the imagination department.

  • Shield level Mythisch
  • Watchers Gremlins im Standby
  • Last attack Story folgt nach Registrierung