Open
Cached
·
just now
75/100
SECURITY SCORE
Certificate Information
Subject
CN=www.uppercasegaming.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 08, 2025
Valid Until
January 06, 2026
45 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8F:AC:B8:D9:E9:4E:EC:77:D9:04:51:A9:EB:3B:FF:1C:01:94:83:4F:32:D8:27:ED:49:AE:E2:AE:AD:02:DF:E1
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
a2zcode.com
schedule-dev.addgreen.jp
alectoconsulting.com
www.aleks.codes
dashboard.apexcounselingmt.com
www.apiprivacy.com
visitor-dev.atlas-apps.link
ewiscloud.auxswot.com
www.b2bvalker.com.ar
ballparkvisits.com
bloomplex.com
bluecredits.org
caarya.life
prototype.cake.io
www.carlosmachado.me
pay.chaser.io
www.clubsjarel.nl
cnybridges.org
3es.co.in
admin.northgateestates.co.zw
coastertokyo.com
crainicu.com
esk-qr.dasistan.com
www.developerweekend.com
painel.doctorclin.com.br
www.dronvyas.com
easyleads.app
acehack.uem.edu.in
elmasdokum.com
sponsor.fitoutawards.ie
short.fota.io
api.getpacked.de
sounds.stage.getshuffleboard.com
sa.giamban.co
gosweetsgo.com
guptafc.in
cockpitch.gustavogonzaga.com.br
howsplit.xyz
spartansvietnam.impactwrap.com
servicity.in.ua
www.jagokissan.com
opencardsproject.klek.uk
games.kobalab.works
www.koncertzobyvaku.cz
gacha.koneta.click
korjausinfo.fi
student-stg.kyons.vn
daytmp.labmkr.com
www.loupetheapp.com
www.matiushev.me
mockdrafthero.com
account.mocklets.com
seo.myappstoolbox.com
myfirstchoicefm.com
www.mypips.app
bulk.nazeerfoods.com
app.ncast.com.br
www.nuvitolpharmaceuticals.com
www.ottovandepol.nl
use.parkalot.io
app.plan2win.be
playeuchre-online.com
www.pocketsidur.app
www.policyaid.in
pooli.app
qa.portal-patient.com
cardapio.pousadadoalagado.com.br
pp.care
pqswitch.io
admin.queueme.co
www.quickzz.com
ranasales.com
roonessentials.com
www.sagardoyschool.com
screvo.hu
teleconsultaqa.sdsigma.com
stg.smartlena.com
www.snackdriven.com
sofiafernandeslashmaster.pt
www.souvenirmax.com
admin.splainer.in
app.statik-nachweis.de
moneyball.games.tetherstudios.com
qc.thatsmybuddy.com
apiprod.theboxmarket.vn
app.thesama.in
tonys-barber.de
terms.tourbutler.app
trackyatra.in
fit.trainertechpro.com
tredco.fi
staging.turborad.com
uneau.com
www.uppercasegaming.com
url.chat
app.visable.com
link.wifiesta.com
staging-chat.yepic.ai
yovento.dev
zendengreenpurp.com
Other domains in certificate