Skip to content
WebsiteValidator
SecurityCritical Affects your score

Certificate covers the hostname being served

SEC_TLS_HOSTNAME_COVERED

Checks the scanned hostname against the certificate's subject alternative names, including wildcard entries. A certificate that does not cover the hostname triggers the same interstitial as an expired one, and it is easy to miss when the apex and www forms are configured separately.

  • Free, no signupNo account, no card
  • No AI in the score986 deterministic rules
  • Nothing publishedYour scans stay yours
  • Answers in secondsQuick scan, no browser

How this rule is weighted

Importance
9 / 10
How much this matters relative to other rules.
Confidence
SPECIFICATION
A standard says so: HTML, WCAG, an RFC or Google's own documentation.
Severity
critical
How the finding is presented when it fails.
Scoring
Counts
A failure costs points in its category.

Impact is importance multiplied by the confidence tier’s weight — SPECIFICATION 1.0, RESEARCH 0.7, EMERGING 0.3, EXPERIMENTAL 0.1. Two rules backed by the same class of evidence therefore always carry the same weight, which is what makes the score reproducible rather than hand-tuned.

Questions about this rule

Does SEC_TLS_HOSTNAME_COVERED affect my score?
Yes. It is an importance 9 rule at SPECIFICATION confidence, so a failure costs 9 × 1 points of impact in the Security category before that category is normalised to 100.
What does SPECIFICATION confidence mean?
A standard says so: HTML, WCAG, an RFC or Google's own documentation. Confidence is a declared tier rather than a per-rule number, so every rule backed by the same class of evidence carries the same weight - which is what makes the score reproducible instead of hand-tuned.
How do I check SEC_TLS_HOSTNAME_COVERED on my own site?
Paste your URL into the box above and it runs only this rule, usually in a couple of seconds. It is also included in the Security checker and in a full scan.

Tags

  • security
  • tls
  • certificate
  • transport

Related Security rules

Run the Security checkerAll 986 rules