HTTPS, SSL & Security Report for rakuten.co.jp

This report summarizes how well rakuten.co.jp is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.

Partially secureScore80/100Last checked: 6 Mar 2026 at 21:30 UTCRefresh report
HTTPS

Enabled

HTTP → HTTPS

Yes

TLS

B+ · 1.2, 1.3

Security headers

0/6

Detailed checks

HTTPS availability

The site is reachable over HTTPS.

Why it matters: HTTPS encrypts traffic and protects user data.

HTTP to HTTPS redirect

Requests to HTTP are redirected to HTTPS.

TLS & CertificateB+

ValidYes
IssuerC=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1
Expires2026-05-19
Days until expiry74 days

Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.

To improve your grade

  • Reach 85+ points for A- (currently 80).
Grade breakdown1 thing to improve for a higher grade →
80/100 pts
HTTPS Connection
+25/25
HTTP to HTTPS Redirect
+20/20
Valid SSL Certificate
+20/20
Certificate Not Expiring Soon
+10/10
Fast Response Time
+0/10
Short Redirect Chain
+5/5
HSTS Enabled
+0/5
Security Headers
+0/5

Requires 4 of 6 headers and Content-Security-Policy (CSP).

To improve your grade

  • Reach 85+ points for A- (currently 80).

Security headers0/6

    Score: 0 of 6 headers present. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required.

    HSTS (HTTP Strict Transport Security)Disabled

    • EnabledNo
    • On HSTS preload listNo
    Submit or verify on hstspreload.org

    Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.

    We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.

    HTTP/3 (QUIC)

    Not advertised

    The server does not advertise HTTP/3 (QUIC) via the Alt-Svc header.

    DNS Security

    CAA: Not set · DNSSEC: Not signedExpand
    CAANot set
    DNSSEC
    Not signed

    No CAA records. Any CA can issue certificates. Consider adding CAA to restrict issuance.

    Mixed content

    None detected

    No HTTP resources were detected on the HTTPS page.

    Redirect chain10279ms total

    When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.

    1. 1.http://rakuten.co.jp228ms
    2. 2.https://www.rakuten.co.jp/10051ms

    Domain owner? If you want this report removed or made private, contact us.