Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=grandarm.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 20, 2026
Valid Until
May 21, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D7:8B:FC:20:72:58:7F:A5:7B:E9:73:FD:13:12:B4:6A:CB:07:A1:92:63:7D:2D:EF:35:79:52:22:32:E2:1B:A8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
settle.link *.settle.link *.admin.settle.link *.api.settle.link *.app.settle.link *.cnjhqzvd.settle.link *.cpyvfdtb.settle.link *.demo.settle.link *.dev.settle.link *.ehskndcl.settle.link *.elvcgjxb.settle.link *.exdfnmiz.settle.link *.ezvlncpr.settle.link *.fnlvwzqm.settle.link *.fxhmbnjp.settle.link *.hostmaster.settle.link *.ihywqzge.settle.link *.jaghouye.settle.link *.jbdgeqpa.settle.link *.jgudwbcz.settle.link *.keqxawfd.settle.link *.klbipyjd.settle.link *.kueomzkayehlq.settle.link *.lfdemjoh.settle.link *.lvyasjze.settle.link *.lwfxvton.settle.link *.mbpzvcok.settle.link *.members.settle.link *.mhotfcbx.settle.link *.nmlsqxei.settle.link *.nzhovbws.settle.link *.pckloswf.settle.link *.pgowqsvz.settle.link *.qadbysjk.settle.link *.qsrykedh.settle.link *.qxemrbut.settle.link *.qzahpogl.settle.link *.salnywgd.settle.link *.sldphrzg.settle.link *.srjqpfec.settle.link *.staging.settle.link *.swzltknm.settle.link *.test.settle.link *.tmobile.settle.link *.uat.settle.link *.wjltiaoe.settle.link *.wmxrbdnj.settle.link *.wszbapgowqsvz.settle.link *.wvpqltfe.settle.link *.yerobifz.settle.link

Other domains in certificate

*.bgptools-wildcard-confirmed.grandarm.com *.demo.grandarm.com *.dev.grandarm.com *.ftp.grandarm.com grandarm.com *.grandarm.com *.pop.grandarm.com *.vpn.grandarm.com
*.3210bc16-7b61-44d0-8a82-62b77a47eb90.secureqgiv.com *.3ae05b16-cd51-4e20-82e1-9c9008b2048f.secureqgiv.com *.50a116b3-6813-41b1-b52d-d030ff736d9a.secureqgiv.com *.9ad844a2-6ed5-4a95-b2c6-a890982f8529.secureqgiv.com *.admin.secureqgiv.com *.alpha.secureqgiv.com *.api.secureqgiv.com *.app.secureqgiv.com *.bravo.secureqgiv.com *.chat.secureqgiv.com *.docs.secureqgiv.com *.intranet.secureqgiv.com *.m.secureqgiv.com *.mx7.secureqgiv.com *.my.secureqgiv.com *.pdhmiadmin.secureqgiv.com *.portal.secureqgiv.com *.rd.secureqgiv.com *.rdweb.secureqgiv.com *.remote.secureqgiv.com *.samara.secureqgiv.com secureqgiv.com *.secureqgiv.com *.shop.secureqgiv.com *.ssl.secureqgiv.com *.store.secureqgiv.com *.uongirdweb.secureqgiv.com *.www.secureqgiv.com
*.pay.sosi.life sosi.life *.sosi.life