HTTPS, SSL & Security Report for m.youtube.com

This report summarizes how well m.youtube.com is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.

Partially secureScore70/100Last checked: 8 Aug 2026 at 23:44 UTC
HTTPS

Enabled

HTTP → HTTPS

Yes

TLS

F · 1.2, 1.3

Security headers

5/6

Detailed checks

HTTPS availability

The site is reachable over HTTPS.

Why it matters: HTTPS encrypts traffic and protects user data.

HTTP to HTTPS redirect

Requests to HTTP are redirected to HTTPS.

TLS & CertificateF

Redirects to www.youtube.com — same certificate covers both hosts.

ValidNo
IssuerC=US, O=Google Trust Services, CN=WR2
Expires2026-10-12
Days until expiry64 days

Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.

To improve your grade

  • Fix the SSL certificate to improve the grade.

Monitor this domain

We'll check SSL grade, HTTPS, redirects, and security headers automatically. Email only when something changes.

Start monitoring — freeOne-click account with Google, GitHub, or email. No password.

Free: 1 domain, weekly. Plans from €7/mo — daily checks, up to 50 domains, history & white-label PDF.

Grade breakdown1 thing to improve for a higher grade →
70/100 pts
HTTPS Connection
+25/25
HTTP to HTTPS Redirect
+20/20
Valid SSL Certificate
+0/20
Certificate Not Expiring Soon
+10/10
Short Redirect Chain
+5/5
HSTS Enabled
+5/5
Security Headers
+5/5
Modern TLS (no 1.0/1.1)
+0/10

To improve your grade

  • Fix the SSL certificate to improve the grade.

Security headers5/6

  • HSTS
  • CSP
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy

Score: 5 of 6 headers effective. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required.

Cache-Control includes no-store on the HTML response. Browsers will not cache the document; ETag and conditional requests (304) are effectively disabled. Often intentional for authenticated pages; for public pages consider private with max-age or removing no-store if you want HTTP caching.

HSTS (HTTP Strict Transport Security)Enabled

  • EnabledYes
  • Max-Age365 days
  • PreloadNo
Submit or verify on hstspreload.org

Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.

We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.

HTTP/2

Negotiated (ALPN h2)

ALPN: h2

HTTP/3 (QUIC)

Advertised + confirmed

Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000

Active QUIC negotiation succeeded (curl --http3).

DNS Security

CAA: Configured · DNSSEC: Not signed · HTTPS record: PresentExpand
CAAConfigured

Allowed issuers: pki.goog

DNSSEC
Not signed
HTTPS Record
Present

ALPN: h2, h3

Mixed content

None detected

No HTTP resources were detected on the HTTPS page.

Redirect chain315ms total

When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.

  1. 1.http://m.youtube.com30ms
  2. 2.https://m.youtube.com/108ms
  3. 3.https://www.youtube.com/?app=desktop177ms

Recommendations for m.youtube.com

Based on this scan, here are the 3 next steps that would most improve security and SEO for m.youtube.com.

  1. Fix the SSL certificate

    High impact

    The certificate for m.youtube.com is not valid. Browsers show a full-page warning for invalid certificates, which drives most visitors away immediately.

  2. Add 1 missing security header

    Recommended

    m.youtube.com sends 5 of 6 recommended security headers — missing: Referrer-Policy. Most take one line of server config and protect against clickjacking, MIME sniffing and data leaks.

  3. Disable TLS 1.0 and 1.1

    Recommended

    m.youtube.com still accepts TLS 1.0 and/or TLS 1.1. Modern browsers have removed those versions; leaving them on costs grade points and fails many compliance scans. Restrict the server to TLS 1.2 and 1.3.

Show this badge on your site

Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:

SSL grade badge for m.youtube.com← live preview, updates automatically
<a href="https://httpsornot.com/report/m.youtube.com?utm_source=badge" target="_blank" rel="noopener">
  <img src="https://httpsornot.com/badge/m.youtube.com.svg" alt="SSL grade for m.youtube.com — checked by HTTPS Checker" height="20" loading="lazy" />
</a>

Domain owner? If you want this report removed or made private, contact us.