Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.zappybit.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 05, 2025
Valid Until
January 03, 2026
41 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D7:08:B3:CD:F6:00:80:81:84:99:45:A9:3B:F0:5A:80:5A:A1:70:1B:F0:DE:23:5A:59:08:E0:5D:D3:67:EC:09
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
3dmusica.com
tbsglowdia.app.1on1navi.com
208busybeehandyman.com
adsconstructiongroup.com
www.agrocontrole.ch
aifriends.in
www.alvarezcarro.es
ambrosegaming.com
angelnumbersdecoded.com
app.archerypath.com
mt.ashukumar.com
share.asvanu.lk
www.beg-ingenieure.de
edit.bernd-heidt.de
sky.blockchain-exp.com
ci-candidate.cnect.jobs
asus.poweredby.yit.co.il
www.heattech.co.in
amonto.co.th
engram.cogx.fr
coldemailgenius.com
doctor.mymedicine.com.mm
bash-uiux.com.ng
www.cwinsolutions.tech
portfolio.dark-lord.xyz
workshop.dataknobs.com
stripe.for.dinii.jp
data.staging.einfachgast.de
procesos.elebano.com
www.erickcabeleireiro.com.br
cms.ethico.digital
cassi.iron-fit.facss.io
www.gabrycina.it
www.getchart.online
gl.getglue.co
release.getoutfit.app
www.gigigo.hu
mail.glassmaytes.com
www.gorillasports.lv
greendigitalcards.com
hoewerktduurzaam.nl
hotg.ai
link.how.fm
www.huaybulls.com
humanaassist.app
ifeassessoria.com.br
imbianchinolegnano.it
tui-id-testing.input4you.be
jesusgpt.in
www.maths.joshid.co.uk
login.ju.studio
alpha.keegym.io
app.lasyn.com
locallens.space
mamazetjegoed.nl
mariusjakobsen.no
marmartahery.com
moijasns.site
msmc.jp
namadahub.org
www.nammaimeenagam.com
swisshosp.nt-me.link
onerun.app
openteam.space
www.plataformasierrachiva.org.es
pagoapp.cl
marynarska.parkcash.io
www.partiapolexit.org
www.pixraider.com
app.preadiccion.com
www.preadiccion.com
www.punitchaurasiya.in
creators.qfix.ai
policy.quicksave2u.com
hbd.rainago.com
aplit.raminaji.me
rencityart.org
my.rootstudio.ng
www.saintleocamps.com
www.sattaking7.online
galatasaray.scouthub.app
uat.seventen.org
droidlab.slash.ro
soozane.com
demo.spork.cloud
connectedliving-staging.thunderlabs.tech
torrelatas.com.br
toworky.com
connect4.trandrew.ca
tz.gl
residentfees.veltech.com.au
www.vidhyarthi.org
deeplinks.specialday.aux1.vobo.com
www.wmrha.org
service.eu.wowworks.org
get.yapeal.ch
www.zappybit.com
app.zfluence.com
admin.zist.be
zknzcode.com
Other domains in certificate