Zoom

Zoom

Verified Audit

zoom.us

Last evaluated: September 2026
Overall Score
81%
Security Grade A
0Good
19

Checks Passed

4

Warnings

1

Failed Issues

24

Total Evaluated

Category Score Breakdown

Transport / TLS
94%
Security Headers
78%
Cookies & CORS
86%
DNS & Email
90%
Secrets & Files
100%
Attack Surface
80%

Security Topology Tree — zoom.us

Interactive node visualization showing security controls, certificates, headers, and risk posture.

Interactive Tree Graph
Generating Domain Topology...

Audited Security Controls (8)

Transport & TLS

HTTPS Enforcement & Modern TLS

Verifies encrypted transport, cipher strength, and absence of legacy protocols.

Fix: Maintain TLS 1.3 with forward secrecy.

critical
Passed
Transport & TLS

Strict-Transport-Security (HSTS)

Forces modern browsers to communicate exclusively over HTTPS.

Fix: Configure max-age >= 31536000 with includeSubDomains.

high
Passed
HTTP Security Headers

Content Security Policy (CSP)

Restricts sources from which scripts and styles can load to prevent XSS.

Fix: Adopt strict-dynamic nonces and eliminate unsafe-inline.

critical
Failed
HTTP Security Headers

Clickjacking Protection (X-Frame-Options)

Guards against clickjacking and UI redressing attacks.

Fix: Set X-Frame-Options to DENY or SAMEORIGIN.

high
Passed
Cookies & CORS

Cookie Security Flags (HttpOnly & Secure)

Protects session tokens from theft via client-side scripts.

Fix: Mark all session cookies HttpOnly and Secure.

critical
Passed
DNS & Email Trust

Email Spoofing Defense (SPF & DMARC)

Validates SPF and DMARC enforcement to prevent domain impersonation.

Fix: Enforce DMARC p=quarantine or p=reject.

high
Passed
Secrets & Exposure

Public Secrets & Sensitive File Exposure

Probes for .env, .git, backups, and exposed credentials in client bundles.

Fix: Clean scan: no leaked keys or exposed files found.

critical
Passed
Attack Surface & Probing

Subdomain Takeover & CNAME Radar

Audits DNS records for dangling pointers to abandoned cloud services.

Fix: No dangling DNS records detected.

high
Passed
Continuous Drift Monitoring

Protect your production site against configuration drift. Igris Radar can audit zoom.us daily and notify your team via Slack or Email if a certificate expires or headers are removed.

Audit Your Own Domain

Run all 90+ security checks against your website for free. Instant results in under 30 seconds with no installation required.