77/100 SECURITY SCORE

Certificate Information

Subject
CN=oticamax.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 15, 2025
Valid Until
February 13, 2026 83 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3C:87:85:74:6D:7D:48:13:CE:97:ED:67:A4:B6:72:5F:B6:87:70:68:13:FA:04:3C:4A:2F:12:B4:CE:57:0F:9B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
afltriviaadmin.sqwadhq.com miamiohhockey.sqwadhq.com

Other domains in certificate

downloads.010pixel.com
www.116os.de
cartyx-h5.advlove.io
www.alelian.nl
askpdf.applora.io
videowall.intg.appslatam.com
www.astronautslabs.com
atlantier.com
badmint.one
www.baserobot.co
cica.benjaminkomjathy.hu
rate.bistrochat.com
app-stage.blankstreet.com
web.braav.co
chinese-speak.com
cloudssound.com
v.collegiatecomposites.com
coneytechnologies.com
corner.dev
cosaschidas.com
up-and-up-invite.crio-server.com
dcpoolservice.com
dixiecustoms.com
app.dronelink.com
dsrlglobal.com
dusakabincibodrum.com
www.eiendomsappen.com
controlpanel.eon.soy
peter.esenwa.dev
evitalobo.com
guildbot.exeterguild.org
assessment.falconconsulting.fr
web.footyamigo.com
code.foureyedjimmy.com
fruitjemee.be
fuzatto.com
proyectos.ghyasa.com
globalblockcertseducationcenter.org
www.gregcuesta.com
dev.support.grupoxalka.com
firecloud.haneesh.in
auth-stage.homesy.ch
burger.hthieu.dev
ads-management.hutupia.com
immigrationnationusa.com
link.investissement-locatif.com
jualbelilaptopsbekas.com
kabatas.nl
www.kingsclub.games
www.leadstages.com
learnrussianfree.com
casting-staging.lefty.io
lim-arquitectura.com
lounge111.com
goodkarma.madhive.com
auth.mandbadak.live
www.marian-klose.com
menuplanner.dev
summit3.montblanc.com
mridul.dev
www.mwk.io
app.myhoneystory.com
neelus-test.needleandstitch.ca
roots-staging.nextinline.io
dental.notes-hub.com
omkaraps.com
oncediecinueve.com
oticamax.com
papa-rhodes.com
park.best
www.pastepool.com
pinelinemedia.com
outfitby.pixoby.space
auth.playbook.vc
www.pxl2rem.com
albayleo.rcinvita.com
web.rizz.app
www.sarahsurrette.com
www.scherbenkinder.de
seduni.org
www.sevora.pro
singinglessonsreading.com
sludgefunk.com
link.squadle.com
www.squidcreators.com.br
stellaraya.com
swcollection2187.com
www.teachiq.com
www.theideaproject.org
tsdclientstaging.thesoftwaredispensary.com
math.time8b.com
oappsnet.toborlabs.com
tokn.trade
cycleday.trowbridge.tech
udonproject.com
www.upbias.com
valasek.dev
waving.es