Domain check
Running TLS, DMARC, BIMI, DNS, headers, and MTA-STS checks in parallel...
TLS / SSL
DMARC
BIMI
DNS health
Headers
MTA-STS
Subdomains
Domain check
Running TLS, DMARC, BIMI, DNS, headers, and MTA-STS checks in parallel...
TLS / SSL
DMARC
BIMI
DNS health
Headers
MTA-STS
Subdomains
Domain check
6 sections checked · TLS 173ms · DMARC 121ms · BIMI 119ms · DNS 429ms · Headers 158ms · MTA-STS 37ms
TLS check for
Checked 5/14/2026, 10:48:24 PM · 173ms
Functional but improvable. Look at TLS 1.3 / HSTS.
286d until expiry
Or share this URL with the team that owns the records.
Subject Alternative Names (1)
CN=sony.com
issued by CN=Amazon RSA 2048 M01, O=Amazon, C=US
CN=Amazon RSA 2048 M01, O=Amazon, C=US
issued by CN=Amazon Root CA 1, O=Amazon, C=US
CN=Amazon Root CA 1, O=Amazon, C=US
issued by CN=Starfield Services Root Certificate Authority - G2, O=Starfield Technologies, Inc., L=Scottsdale, ST=Arizona, C=US
CN=Starfield Services Root Certificate Authority - G2, O=Starfield Technologies, Inc., L=Scottsdale, ST=Arizona, C=US
issued by CN=Starfield Services Root Certificate Authority - G2, O=Starfield Technologies, Inc., L=Scottsdale, ST=Arizona, C=US
Negotiated: TLSv1.3 · TLS_AES_128_GCM_SHA256 (TLSv1.3)
TLSv1
Not supported
not supportedTLSv1.1
Not supported
not supportedTLSv1.2
Supported
TLSv1.3
Supported
No Strict-Transport-Security header was returned.
AI-assisted remediation
Wiredepth Pro sends this report to our AI engine and streams back a 30-day rollout plan tailored to sony.com, with provider-specific tips when we can infer them from the data. 10 playbooks per month on Pro, 100 on MSP.
DMARC check for
Checked 5/14/2026, 10:48:24 PM · 121ms
Monitor-only (p=none). Spoofers are not blocked.
v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1;
Found on the apex domain.
v=spf1 include:amazonses.com include:spf.protection.outlook.com include:spfa.sony.com ip4:121.100.43.221 ip4:185.136.188.108 ip4:185.136.189.108 ip4:121.100.43.225 ip4:121.100.43.226 ip4:139.60.152.0/22 ip4:148.105.8.0/21 ip4:160.33.101.112/28 ip4:160.33.194.224/28 ip4:160.33.194.232 ip4:160.33.194.233 ip4:160.33.194.234 ip4:160.33.194.235 ip4:160.33.96.128/28 ip4:185.132.182.190 ip4:185.132.183.11 ip4:185.183.30.70 ip4:198.2.128.0/18 ip4:205.201.128.0/20 ip4:208.74.204.0/22 ip4:212.100.250.11 ip4:212.100.250.16/29 ip4:37.188.101.80/28 ip4:46.19.168.0/23 ip4:5.61.115.112/28 ip4:5.61.115.80/28 ip4:5.61.115.96/28 ip4:5.61.117.112/28 ip4:5.61.117.80/28 ip4:5.61.117.96/28 ip4:52.222.62.51/32 ip4:52.222.73.120/32 ip4:52.222.73.83/32 ip4:52.222.75.85/32 ip4:54.186.193.102/32 ip4:83.138.165.68/31 ip4:91.207.212.191 ip6:2607:fd28:0102:1:1::/80 ip6:2607:fd28:0102:3:300::/80 ip4:101.231.129.3 ip4:101.231.129.4 ip4:3.93.157.0/24 ip4:3.210.190.0/24 ip4:18.208.124.128/25 ip4:54.174.52.0/24 ip4:54.174.57.0/24 ip4:54.174.59.0/24 ip4:54.174.60.0/23 ip4:54.174.63.0/24 ip4:139.180.17.0/24 ip4:141.193.184.32/27 ip4:141.193.184.64/26 ip4:141.193.184.128/25 ip4:141.193.185.32/27 ip4:141.193.185.64/26 ip4:141.193.185.128/25 ip4:143.244.80.0/20 ip4:158.247.16.0/20 ip4:108.179.144.0/20 ip4:66.159.233.15 ip4:66.159.234.91 ip4:66.159.233.14 ip4:66.159.234.90 ip4:66.159.232.89 ip4:143.55.149.237 ip4:66.159.233.25 ip4:66.159.234.101 ip4:101.231.129.43 ip4:216.139.64.0/19 ip4:211.125.130.0/24 ip6:2001:cf8:0:b0::/64 -all
AI-assisted remediation
Wiredepth Pro sends this report to our AI engine and streams back a 30-day rollout plan tailored to sony.com, with provider-specific tips when we can infer them from the data. 10 playbooks per month on Pro, 100 on MSP.
BIMI check for
Checked 5/14/2026, 10:48:24 PM · 119ms
No BIMI record published.
looked up: default._bimi.sony.com
No VMC URL declared. Required by Gmail and Apple Mail to display the logo.
BIMI requires DMARC p=quarantine or p=reject with pct=100. Currently: policy none, pct 100.
for sony.com
Replace the URLs with the real locations of your SVG Tiny PS logo and VMC pem. Both must be HTTPS with a trusted cert. Gmail and Apple Mail also require DMARC at p=quarantine or p=reject and pct=100.
default._bimiv=BIMI1; l=https://sony.com/bimi-logo.svg; a=https://sony.com/bimi-vmc.pemAI-assisted remediation
Wiredepth Pro sends this report to our AI engine and streams back a 30-day rollout plan tailored to sony.com, with provider-specific tips when we can infer them from the data. 10 playbooks per month on Pro, 100 on MSP.
DNS health for
Checked 5/14/2026, 10:48:24 PM · 429ms
Some critical hardenings missing.
No CAA records published. Any CA can issue certs for this domain.
checked IP: 143.55.149.237 (MX mxb-001d1709.gslb.pphosted.com), 66.159.232.89 (MX mxa-001d1709.gslb.pphosted.com)
Domain intel on sony.com
✓ Malware / phishing intel: clean
Domain is not on any malware-distribution feed we track.
✓ Active threat intel: clean
No active C2 / botnet IOCs against this domain.
Registered 1989-07-07 - established
Established domains rarely host phishing infrastructure.
for sony.com
Let's Encrypt is the most common free CA. If you also use a paid CA (Sectigo, DigiCert, etc.), add additional `0 issue "<ca-host>"` records for each.
@0 issue "letsencrypt.org"Authorise wildcard cert issuance. Drop this record if you never need wildcard certs.
@0 issuewild "letsencrypt.org"Where to send incident reports if a CA detects an unauthorised issuance attempt. Point at a real mailbox.
@0 iodef "mailto:[email protected]"AI-assisted remediation
Wiredepth Pro sends this report to our AI engine and streams back a 30-day rollout plan tailored to sony.com, with provider-specific tips when we can infer them from the data. 10 playbooks per month on Pro, 100 on MSP.
Security headers for
https://www.sony.com/ · status 403 · checked 5/14/2026, 10:48:24 PM · 158ms
followed 1 redirect: 301 sony.com/ → 403 www.sony.com/ → 403
Severe gaps in defensive headers.
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; # After 30+ days at this max-age with includeSubDomains, submit at hstspreload.org. add_header Content-Security-Policy "default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'" always; # Tight starting policy. Iterate by inspecting CSP-Report-Only violations on a staging branch first. add_header X-Frame-Options DENY always; # Backstop for older browsers; CSP frame-ancestors handles modern ones. add_header X-Content-Type-Options nosniff always; add_header Referrer-Policy strict-origin-when-cross-origin always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), interest-cohort=()" always; # Disables features you almost certainly do not need. Add features back inside the parens if your site does need them.
AI-assisted remediation
Wiredepth Pro sends this report to our AI engine and streams back a 30-day rollout plan tailored to sony.com, with provider-specific tips when we can infer them from the data. 10 playbooks per month on Pro, 100 on MSP.
MTA-STS + TLS-RPT for
Checked 5/14/2026, 10:48:24 PM · 37ms
No MTA-STS at all. Mail in transit is not enforced.
looked up: _mta-sts.sony.com
https://mta-sts.sony.com/.well-known/mta-sts.txt
No TLS-RPT record found. Without it, you do not learn when receivers fail to enforce STS against your domain.
for sony.com
The id is an opaque string. Bump it whenever you change the policy file, otherwise receivers will keep using the cached version.
_mta-stsv=STSv1; id=20260514224824TLS-RPT lets receivers send you JSON reports when STS / DANE fails. Point the rua at a mailbox you actually monitor.
_smtp._tlsv=TLSRPTv1; rua=mailto:[email protected]Host the file below at https://mta-sts.sony.com/.well-known/mta-sts.txt with a trusted TLS cert (no self-signed). Replace the mx: line(s) with each of your real mail servers. Start with mode: testing to collect TLS-RPT failure reports before raising to mode: enforce.
version: STSv1 mode: testing mx: mail.sony.com max_age: 86400
Cloudflare Workers, Pages, or any static host with HTTPS can serve this. The well-known path needs a Content-Type of text/plain.
AI-assisted remediation
Wiredepth Pro sends this report to our AI engine and streams back a 30-day rollout plan tailored to sony.com, with provider-specific tips when we can infer them from the data. 10 playbooks per month on Pro, 100 on MSP.