77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.aokiyamato.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 11, 2025
Valid Until
March 11, 2026 66 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
06:E9:FC:CB:FD:73:E5:72:0B:4D:68:A6:20:E1:EF:12:93:2C:26:44:45:A4:56:5F:10:B4:7A:55:13:22:62:16
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
admin-uat.albumhealth.com

Other domains in certificate

11521882.stratics.io
app.acheckin.vn
alexmontague.ca
alkhabourah.net
andlo.com
www.aokiyamato.com
www.appointmentsone.com
www.arb.yt
arunav.in
avari.technology
biolng.in
blindleister.de
widget.lite.botslovers.com
admin.centroterapeuticocubic.es
www.chinese-speak.com
christmas-calendar.com
www.click2kick.com
greatexport.co.in
registrationforseminar.mobileconnect.co.th
www.ewalker.com.hk
push.automedic.com.pk
session-management.dataplace.ai
clube.drakerly.com
dsgtech.in
ecoluxclean.in
entrant.eia.ie
www.elearncert.com
ficq.org.au
build.flowspark.co
ecim-dev.garibay.xyz
staging.geolocation.fr
www.globalexecconnect.com
gulkilik.com
handsomequest.com
product.herlipto.jp
hillsviewc.co.za
www.huskysoftware.com.ar
www.janainamenezes.com
www.joshuapinti.com
jocundwave.jovialknits.in
www.kayinla87.com
kishangroupelectricals.com
beta-app.lexr.ch
www.lost-vault.com
m1nm1n.com
www.manmanband.com
savor.mapleworkspace.com
www.martinshelley.com
mizastartup.com
mobviberus.ru
cryptonewsalerts.mokimokiteam.com
www.mridulbansal.com
app.muslim.estate
links.onehealth.test.mycareplan.health
app.mytuner-radio.com
arf-pwa.nci-staging.com
admin2.uni.net.vn
link-isa.nibo.com.br
www.nommynommy.com
paroledelcuore.oliocuore.it
cv.omrilevy.dev resume.omrilevy.dev
orangegroveproperties.com
www.ovellocapital.com
paul-copley.com
physioreach.in
app-dev.playplanetx.com
polipics.in
beta.pronaid.com
rajneethi.in
rekor.games
beta.retumittari.fi
www.siet.limited
skkandco.in
www.smartstepacademy.co.za
www.smi-meca.fr
sniply.cc
link.sutes.me
firebase.tana.team
www.tanmoykarmakar.in
manuel.tardivo.dev
taylorconor.com
wordcube.games.tetherstudios.com
www.theironstreetgym.com
fp.themeinnov8.com
astelux.thetislive.com
titantrack.com
www.toagxpress.com
web.trato.com.br
vouchers.qa.uniqgift.com
vardfinancial.ae
acceptance.veeew.com
obs.vens.co
www.visionprofiler.com
vsinger.io
panel.vviinn.com
webplayer-stage-sub.wexer.com
manage.eshare.zenmov.com
zkxjq.com