77/100 SECURITY SCORE

Certificate Information

Subject
CN=dl32.brinias.eu
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 08, 2025
Valid Until
March 08, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DE:95:9E:E9:E4:1F:EC:3A:65:8D:C3:2B:33:29:D4:23:E9:D5:1B:2E:F5:DA:8C:CC:DA:E2:3E:F6:A3:2A:08:87
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
academy.nextmove.nl

Other domains in certificate

wimmersolutions.3diq.com
glyph.acromwell.com
www.adamalcantara.com
aftonomo.com
demo.one.aglive.com
www.agsecurityresearch.com
amascarello.com
link.ameiz.app
www.andreamilio.com
www.arantismusic.com
www.artalgie.fr
support.astrosoul.app
www.balestero.com
baushare.de
web.stg.bizflex.app
bpotecnologia.com
dl32.brinias.eu
calvinnguyen.org
www.candyco.com
cartfuly.app
taslonic.compilorama.com
applinks.countwiz.com
minecraft.cowsrbeefy.com
apphome.ddangkongschool.com
events.deucebilzen.be
www.digitaltidemedia.co.za
console.donetalking.com
cardano.dreamwave.live
ententecitoyenne.ch
www.erikschierboom.nl
auth.eviebikes.com
exarplay.in
findmoonlight.com
gronstedts-timeto.folkofolk.se
get-shrimping.footprint-ai.com
freeriderjumps.com
garushajain.com
getresponse.chat
glossariomatemlibras.com.br
gmr-inventory.com
links.go-work.com
governing.ai
admin.staging.hummingbirdtech.com
projects.hutupia.com
links.uniaph.ibraph.app
duongbuiit2.id.vn
resume.reza.info.bd
app.iportal.africa
jamieepstein.dev
jandson.group
japanverse.co
www.jonas-wanke.com
joncarlost.dev
www.jsoncreative.com
karupattitreats.com
www.kitesprepschool.org
kreditkort.com
kurtzepeda.com
checkin.leaderland.academy
party.liveqa.jp
lookreel.com
staging.pay.lopay.com
lukeharwood.dev
www.manoirangemarie.ca
nuxt.blog2.maxentwickler.site
me-talent.com
mfrancis.dev
millerealm.com
mindupllc.com
minsoft.in
www.monikakurek.pl
life.neophi.com
portalwa.nuverax.com
rangernatural.piticommerce.com
playsoundlist.xyz
www.pokestats.nu
projectthaihub.com
dev-restaurants.roll-app.com
routify.us
sandrasoft.app
auth.savethebudget.com
www.sklabs.app
pro.sterilwize.com
sys9.co.jp
texasvotertracker.com
thegeneralsyfca.org
theidealremodeling.com
thetokyomatrix.com
philips.thewonderofyou.io
toquad.com
wholesale.uggaustralia.com.au
upadhyeclass.com
admin.dev.upstager.co
app.velauto.com.br
admin.vestagroup.vn
www.vnyreddy.com
wheatondaycare.com
wrestlingshuffle.com
zyphlegal.com