Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=wearesouthbound.co.za
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 23, 2025
Valid Until
February 21, 2026
75 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F7:D4:8C:BB:A4:1D:A4:D1:26:93:C4:27:DD:D4:C5:E7:A0:50:A0:F4:93:45:8B:CC:96:39:01:FC:B1:C8:DA:21
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
admin-staging.geneowebapp.com
dev.123games.app
fellowes-modular-config.3dcloud.io
acm-dev.adssets.com
www.alfaserviciointegral.com.ar
uniwa.alias-solutions.net
analytics.apxor.com
www.backquote.dev
door.bartweb.cz
bensbits.org
cbuschedule.xyz
www.cedric-neergaard.dev
www.championsja.com
citadel.tools
rsei.co.in
salonlider.com.ua
p53-dev.credeo.io
ctrlaltbox.com
crossplay.danubehome.com
defimath.ca
www.dimitrigrangeon.com
blog.ecojuntak.dev
dunmsm.edu.pe
egshell.com
www.iamrex.eu.org
app.everythingtypescript.in
butterfly.dokku.explorator.ca
www.fanaro.app
glonkery.pl
beta-app.gohighlevel.com
link.gong.io
discord.hypervr.games
matchmyuni-stage-1.ischoolconnect.com
blabla-bahn.ivlivs.dev
jellyboystudio.com
www.jennisimone.com
job.gi
www.joptep.com
www.kingfisherboatclub.com
api.klay.today
lamachine.preprod.kmp.agency
labsinnova.cl
lastminute-idee.be
www.lazyeee.com
chat.lightnift.com
lotteryofbabylon.com
dev-deep.lynk.us
madereal.ch
www.makethebreak.com
meayuda.cl
metdistcapital.com
www.michaelgathara.com
moderate.midlynk.com
bot.motoverse.games
mtatoursandtravels.com
dev.mugclub.beer
safe.neoufitness.com
painel.visiolens.net.br
system.networkassist.com.au
digital-bloom.nextome.com
noahiarrobinoresume.com
nordev.com.ar
oxford.llc
app.paloaltochineseschool.org
www.popdega.com
ico.pro.earth
proof-of-quantum.com
garbarinolombardo.queliga.com
ramadanorphan.com
sistema.rastrotec.com.br
redlighttour.com
www.relateband.com
job-day.rhinos.fr
rmelist.com
shopbilling.sairamveterinary.com
savingwaste.com
cse.sdsforg.com
support.seino.ai
app.servibat-valluth.fr
thomas.sickert.dev
slatecodex.com
nexusai-nuxt.stylokit.com
sunnyspotpetsitting.com
boardsmash.surajthotakura.com
app.taihelr.com
www.therightsiders.com
genderator.timevault.org
triadkube.com
trive-group.com
link.trueid-preprod.net
uexpop.uexglobal.com
app.ultramixer.com
grey.unsupervized.com
staging.staff.vclass.ac
www.walletrule.com
wearesouthbound.co.za
windventory.com
service.eu.wow-dev.org
zandermackenziecareuk.org
laudomat.zgimage.com
Other domains in certificate