This report summarizes how well facebook.com is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.
Enabled
Yes
B+ · 1.2, 1.3
5/6
The site is reachable over HTTPS.
Why it matters: HTTPS encrypts traffic and protects user data.
Requests to HTTP are redirected to HTTPS.
Redirects to www.facebook.com — same certificate covers both hosts.
| Valid | Yes |
| Issuer | C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 |
| Expires | 2026-08-19 |
| Days until expiry | 7 days |
Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.
To improve your grade
Monitor this domain
We'll check SSL grade, HTTPS, redirects, and security headers automatically. Email only when something changes.
Free: 1 domain, weekly. Plans from €7/mo — daily checks, up to 50 domains, history & white-label PDF.
To improve your grade
Score: 5 of 6 headers effective. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required.
Cache-Control includes no-store on the HTML response. Browsers will not cache the document; ETag and conditional requests (304) are effectively disabled. Often intentional for authenticated pages; for public pages consider private with max-age or removing no-store if you want HTTP caching.
Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.
We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.
Negotiated (ALPN h2)
ALPN: h2
Advertised + confirmed
Alt-Svc: h3=":443"; ma=86400
Active QUIC negotiation succeeded (curl --http3).
Allowed issuers: digicert.com
ALPN: h2, h3
None detected
No HTTP resources were detected on the HTTPS page.
When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.
Based on this scan, here are the 3 next steps that would most improve security and SEO for facebook.com.
Renew the certificate for facebook.com before it expires to avoid downtime. If you use Let's Encrypt or another ACME CA, check that auto-renewal is actually running — expired-but-automated certs are one of the most common outages.
facebook.com sends 5 of 6 recommended security headers — missing: Referrer-Policy. Most take one line of server config and protect against clickjacking, MIME sniffing and data leaks.
facebook.com still accepts TLS 1.0 and/or TLS 1.1. Modern browsers have removed those versions; leaving them on costs grade points and fails many compliance scans. Restrict the server to TLS 1.2 and 1.3.
Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:
<a href="https://httpsornot.com/report/facebook.com?utm_source=badge" target="_blank" rel="noopener"> <img src="https://httpsornot.com/badge/facebook.com.svg" alt="SSL grade for facebook.com — checked by HTTPS Checker" height="20" loading="lazy" /> </a>
Domain owner? If you want this report removed or made private, contact us.