Guest session
Check Detail

download.com · DNS

Passed Grade A
100.0%
Hostname download.com
Check name DNS
last run 15/10/2025 03:55
Result
Passed Grade A 94.9%

Result Detail

DNS
Host Type Answer TTL
34.149.2.250

Result Detail

HEADER
Alerts
  • Cross-Origin-Embedder-Policy: Header missing
  • Expect-CT: Expect-CT missing
  • Access-Control-Allow-Origin: Access-Control-Allow-Origin missing
Normalized headers
date Wed, 15 Oct 2025 01:53:18 GMT
content-type text/html;charset=utf-8
content-security-policy upgrade-insecure-requests
cross-origin-opener-policy same-origin
cross-origin-resource-policy same-origin
origin-agent-cluster ?1
referrer-policy strict-origin-when-cross-origin
strict-transport-security max-age=63072000; includeSubDomains; preload
x-content-type-options nosniff
x-dns-prefetch-control off
x-download-options noopen
x-frame-options SAMEORIGIN
x-permitted-cross-domain-policies none
x-xss-protection 0
x-version 1.1900.0
x-served-by downloadcom
x-resource-id @downloadcom/home
x-page-id home
x-request-id ad27a951-62ec-4d37-bb53-8cc5aa08fac7
permissions-policy accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=()
content-language en-US
cache-control public,max-age=2400,stale-while-revalidate=600,stale-if-error=31536000
surrogate-key home-page home-page-en en-article-list
x-envoy-upstream-service-time 2912
alt-svc h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
tp2-cache hit
content-length 50444
age 149
etag W/"B67ZdCvPOuEjoq8Of1MK+H5deg8="
x-country-code DE
x-region BW
access-control-expose-headers X-Country-Code, X-Region
set-cookie ber-country-code=DE; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-region=BW; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-city=Karlsruhe; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-browser-name=chrome; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-user-platform-id=windows; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-device-type=desktop; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-is-bot=false; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-is-landing=true; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-utm-medium=organic; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-utm-source=; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; ber-utm-campaign=; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure; utm=medium=organic; Expires=Fri, 14 Nov 2025 01:55:49 GMT; Domain=download.cnet.com; Path=/; Secure; _swo_pos=823; Expires=Thu, 30 Oct 2025 01:55:49 GMT; Domain=download.cnet.com; Path=/; Secure
tp-cache hit
vary accept-encoding
accept-ranges bytes
Transport
Check name Status Actual Expected Detail Severity Recommendation
Strict-Transport-Security ✅ Passed max-age=63072000; includeSubDomains; preload max-age>=15768000; includeSubDomains; preload HSTS policy robust Critical Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Expect-CT ❌ Missing enforce; max-age>=86400 Expect-CT missing Medium Expect-CT: enforce, max-age=86400, report-uri="https://report.example.com"
Content Security
Check name Status Actual Expected Detail Severity Recommendation
Content-Security-Policy ✅ Passed upgrade-insecure-requests default-src 'self'; frame-ancestors 'none' default-src 'self'; frame-ancestors 'none' Critical Content-Security-Policy: default-src 'self'; frame-ancestors 'none'
MIME
Check name Status Actual Expected Detail Severity Recommendation
X-Content-Type-Options ✅ Passed nosniff nosniff Value matches recommendation High X-Content-Type-Options: nosniff
Framing
Check name Status Actual Expected Detail Severity Recommendation
X-Frame-Options ✅ Passed SAMEORIGIN DENY or SAMEORIGIN Value accepted High X-Frame-Options: DENY
Privacy
Check name Status Actual Expected Detail Severity Recommendation
Referrer-Policy ✅ Passed strict-origin-when-cross-origin strict-origin-when-cross-origin / same-origin strict-origin-when-cross-origin Medium Referrer-Policy: strict-origin-when-cross-origin
Browser Features
Check name Status Actual Expected Detail Severity Recommendation
Permissions-Policy ✅ Passed accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=() camera=(); geolocation=(); microphone=() camera=(); geolocation=(); microphone=() Medium Permissions-Policy: camera=(), geolocation=(), microphone=()
Cross-Origin
Check name Status Actual Expected Detail Severity Recommendation
Cross-Origin-Opener-Policy ✅ Passed same-origin same-origin Value matches recommendation High Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy ❌ Missing require-corp Header missing High Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Resource-Policy ✅ Passed same-origin same-origin Value matches recommendation Medium Cross-Origin-Resource-Policy: same-origin
Origin-Agent-Cluster ✅ Passed ?1 ?1 Value matches recommendation Low Origin-Agent-Cluster: ?1
Caching
Check name Status Actual Expected Detail Severity Recommendation
Cache-Control ✅ Passed public,max-age=2400,stale-while-revalidate=600,stale-if-error=31536000 no-store, private, max-age=0 no-store, private, max-age=0 High Cache-Control: no-store, private, max-age=0
Legacy
Check name Status Actual Expected Detail Severity Recommendation
X-Permitted-Cross-Domain-Policies ✅ Passed none none Value matches recommendation Low X-Permitted-Cross-Domain-Policies: none
CORS
Check name Status Actual Expected Detail Severity Recommendation
Access-Control-Allow-Origin ❌ Missing Scoped origin (no wildcard) Access-Control-Allow-Origin missing Medium Access-Control-Allow-Origin: https://app.example.com
Information Disclosure
Check name Status Actual Expected Detail Severity Recommendation
Server ✅ Passed Header removed or generic Header not exposed High Remove Server header or set to a generic token
X-Powered-By ✅ Passed Header removed Header not exposed High Remove X-Powered-By header
X-AspNet-Version ✅ Passed Header removed Header not exposed Medium Remove framework version headers
Raw headers
HTTP/2 200 
date: Wed, 15 Oct 2025 01:53:18 GMT
content-type: text/html;charset=utf-8
content-security-policy: upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: strict-origin-when-cross-origin
strict-transport-security: max-age=63072000; includeSubDomains; preload
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
x-version: 1.1900.0
x-served-by: downloadcom
x-resource-id: @downloadcom/home
x-page-id: home
x-request-id: ad27a951-62ec-4d37-bb53-8cc5aa08fac7
permissions-policy: accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=()
content-language: en-US
cache-control: public,max-age=2400,stale-while-revalidate=600,stale-if-error=31536000
surrogate-key: home-page home-page-en en-article-list
x-envoy-upstream-service-time: 2912
alt-svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
tp2-cache: hit
content-length: 50444
age: 149
etag: W/"B67ZdCvPOuEjoq8Of1MK+H5deg8="
x-country-code: DE
x-region: BW
access-control-expose-headers: X-Country-Code, X-Region
set-cookie: ber-country-code=DE; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-region=BW; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-city=Karlsruhe; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-browser-name=chrome; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-user-platform-id=windows; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-device-type=desktop; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-is-bot=false; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-is-landing=true; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-utm-medium=organic; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-utm-source=; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: ber-utm-campaign=; Expires=Wed, 15 Oct 2025 02:25:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: utm=medium=organic; Expires=Fri, 14 Nov 2025 01:55:49 GMT; Domain=download.cnet.com; Path=/; Secure
set-cookie: _swo_pos=823; Expires=Thu, 30 Oct 2025 01:55:49 GMT; Domain=download.cnet.com; Path=/; Secure
tp-cache: hit
vary: accept-encoding
accept-ranges: bytes

Result Detail

SSL
Check name Status Value
certificate chain is complete ✅ Passed 4
root CA is trusted ✅ Passed Trusted
cert valid for ✅ Passed 86
chain certs are valid until ✅ Passed 08.01.2026
CN matches Domainname ✅ Passed download.com
certificate subject ✅ Passed CN=download.com
certificate issuer ✅ Passed C=US, O=Google Trust Services, CN=WR3
signature algorithm ✅ Passed RSA-SHA256
TLS protocol ✅ Passed TLSv1.3 TLS_AES_256_GCM_SHA384
Subject Alternative Names ✅ Passed download.com, www.download.com
Public Key ✅ Passed RSA 2048
Certificate chain
# Common name Issuer Valid until CA
0 download.com C=US, O=Google Trust Services, CN=WR3 08.01.2026 21:53:12 No
1 download.com C=US, O=Google Trust Services, CN=WR3 08.01.2026 21:53:12 No
2 WR3 C=US, O=Google Trust Services LLC, CN=GTS Root R1 20.02.2029 15:00:00 Yes
3 GTS Root R1 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA 28.01.2028 01:00:42 Yes
TLS details
Negotiated protocol TLSv1.3
Cipher suite TLS_AES_256_GCM_SHA384 (256 bit)
Cipher version TLSv1.3
Perfect Forward Secrecy Attention
Earliest chain expiry 08.01.2026 21:53
Fingerprints
SHA-256 A7:07:A5:D0:48:B7:6B:C7:D1:C6:8B:39:9D:D1:EB:19:59:1D:E9:46:A9:FB:94:EC:F5:1F:D4:33:EF:20:66:E9
SHA-1 EB:E7:F6:FE:BE:0D:EF:4C:1D:7C:FF:BC:1C:2E:19:2E:32:21:F4:AC
Revocation
OCSP URLs
http://o.pki.goog/s/wr3/4d4
CRL URLs
Full Name: URI:http://c.pki.goog/wr3/KE4bfPlsk_8.crl
Issuer URLs (AIA)
http://i.pki.goog/wr3.crt
OCSP Must-Staple No
Trust evaluation

Attempted: Yes

Trusted: Yes

OpenSSL diagnostic command
openssl s_client -connect download.com:443 -servername download.com

Result Detail

WAF
Sign up to use!
Ownership verification required

Real WAF results become available after signing up. Until then we show you a small teaser from the imagination department.

  • Shield level Mythisch
  • Watchers Gremlins im Standby
  • Last attack Story folgt nach Registrierung