Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=app.tic-ly.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 07, 2025
Valid Until
March 07, 2026
88 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
17:EB:9A:F6:ED:CB:A5:BB:71:87:3A:3A:8E:F7:71:AE:0D:ED:A6:47:F3:0E:0C:3B:DD:1E:5C:00:F4:9F:2D:E4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
app.martinelliimobiliaria.com.br
student.2xcell.in
www.aapkiaastha.shop
corp.airbuy-japan.com
aishar.ca
www.aishar.ca
alcrystalrealestate.com
apartmentprime.com
salonadliye.artesdeilusion.com
app-stage.atria.mobi
bigbullresearch.com
bikejo.com
cafecohort.com
casahouse.ai
pixels.chillbear.club
utility.climateresponse.com
www.kastaraocean.co.id
st-dinoar.spacetalk.co.kr
suvarnabhumihotel.co.th
codefix.be
conmigoapp.com
daarbit.com
development.envisiondj.com
borstanders.enzoft.se
falconcrms.com
www.finisher.co
static-bkup.fitnessbuddyapp.com
app.flipword.io
fongbi.com
lieferschein.galvaswiss.ch
rectangle-art.garrettroell.com
george-barnard.com
ghostkollective.com
www.graced.world
m.grupidating.com
www.gvpcontabilidade.com.br
calculator.harkness-screens.com
edu.hermonkohima.com
bbraun.hrestart.com.br
links.ilewatt.fr
illite.io
illuminatibrotherhood.vip
inboxthat.com
giver.indefini.do
plugin-canary.interplay.io
janeisthebest.com
johnebejer.com
firebase-test.jonathanperret.net
www.joneschan.net
juttame.ch
kairo.tr
www.keuningsoftware.nl
kingdomdeathmanagement.com
resume.knox.ru
dev.fleet.labs.ws
lahenlvi.fi
timelapse.luxtechnical.co.uk
www.massagetherapie-kurz.de
www.meedocument.in
www.menyja.co
mithrilsoftware.com
dev-console.mqdcapp.com
www.my-maiden.com
scanner.myrealfood.app
mystoreprices.com
www.norbertczarnek.pl
oneheart.marketing
powerchallenge.ayp.org.hk
auth.pawpaws.com.co
phoenixsuppliesandsolutions.com
polis.work
pwnasaurusgames.com
nabeasytap.qps.io
rankingdrawing.com
recessionmonitor.com
www.runningchampions.com
links.saleshub.jp
go.scoopanalytics.com
seerflightsystems.com
admin.shoppinglive.fr
www.admin.shoppinglive.fr
songbird.onl
www.space-time.tv
www.spencerensemble.co.uk
stperla.vn
www.szef-inspiruje.pl
share.tak.live
portal.tere.cr
www.thepsychologytalk.com.au
app.tic-ly.com
torigan.com
apps.trick17.it
www.udlejningsventilator.dk
veerataxi.in
vestico.co
vinayakamultispecialityhospital.com
livego-stg.vonder.io
zakatiwana.info
pdfmanager.zenithcodestudio.com
zitounapressing.com
Other domains in certificate