qa-profile.stripe.com security report
Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.
63risk
Elevated
Several issues worth triaging this week.
0Critical
2High
3Medium
3Low
1Info
Collected 2.5sfrom cache
- Certificate Transparency1
- DNS resolution0
- Network ownership
- CDN / WAF detection
- Exposed ports & CVEs
- Registration
- DNS posture0
- Email authentication0
- Certificate
- Security headers2
- Archived URLs
- Analysis9
- noteCertificate inspection is unavailable in this runtime.
final https://qa-profile.stripe.com/status 530time 27msstack cloudflare
- ✗http:// redirects to https://
- ✗Strict-Transport-Security
- ✗Content-Security-Policy
- ✓Clickjacking protectionSAMEORIGIN
- ✗X-Content-Type-Options
- ✓Referrer-Policysame-origin
- –Permissions-Policyoptional
- –security.txt publishedoptional — tells researchers where to report bugs
- –No MX records — domain does not receive mail
- ✗SPFno record
- ✗DMARCno record
- –MTA-STSn/a
- !DNSSECanswers can be forged
- –CAAany CA may issue
- –IPv6 (AAAA)IPv4 only
- ✓0 nameservers
- ✓Registered with SafeNames Ltd.31.0 years old
- ✓Registration expiry369 days2027-09-11
- ✓Transfer lockclient delete prohibited, client transfer prohibited, client update prohibited, server delete prohibited, server transfer prohibited, server update prohibited
- ✓4 nameservers at registry
Archived URLs
Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.