Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=openatreetmap.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026
75 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1E:95:98:38:58:BE:DC:F0:3D:E9:3B:16:AA:35:97:3E:34:BA:E1:87:8B:B2:68:12:34:88:3F:EC:BF:B8:32:87
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
openflat.it
*.openflat.it
aaltoma.net
*.aaltoma.net
aavv28.xyz
*.aavv28.xyz
aba-ws.org
*.aba-ws.org
accc.lol
*.accc.lol
accessgrowthsolutionleaders.com
*.accessgrowthsolutionleaders.com
accountingperspectives.com
*.accountingperspectives.com
nexusvc.biz
*.nexusvc.biz
neymar-88sirsak.biz
*.neymar-88sirsak.biz
nezha.love
*.nezha.love
ngqfjwyx.xyz
*.ngqfjwyx.xyz
nhaawpk.cc
*.nhaawpk.cc
nicolahaswell.com
*.nicolahaswell.com
nihatberker.net
*.nihatberker.net
niken-hkb77.sbs
*.niken-hkb77.sbs
nikkeiex.org
*.nikkeiex.org
nomenu.co
*.nomenu.co
nonconversant.com
*.nonconversant.com
nooralmamzarmedicaltreatment.com
*.nooralmamzarmedicaltreatment.com
novafins.pro
*.novafins.pro
nowmusic.it
*.nowmusic.it
noxveeatgw.org
*.noxveeatgw.org
nr4.top
*.nr4.top
ntopak.biz
*.ntopak.biz
nurse-uae2.click
*.nurse-uae2.click
nutrisolis.com
*.nutrisolis.com
nutritango.com
*.nutritango.com
nuttallbrown.us
*.nuttallbrown.us
nvdacrpt.website
*.nvdacrpt.website
nwosoldier.com
*.nwosoldier.com
nygtvx4mg.buzz
*.nygtvx4mg.buzz
nywgryl.com
*.nywgryl.com
oakstreetchic.com
*.oakstreetchic.com
offerforme.it
*.offerforme.it
ohiofiresuppression.net
*.ohiofiresuppression.net
ojmbzve528.vip
*.ojmbzve528.vip
okjhg.co
*.okjhg.co
oldtown.us
*.oldtown.us
onecitymail.com
*.onecitymail.com
onlineforyou.it
*.onlineforyou.it
onlineleagueofpoker.it
*.onlineleagueofpoker.it
openatreetmap.org
*.openatreetmap.org
optezorpa.org
*.optezorpa.org
optimafunds.org
*.optimafunds.org
oreequeg.com
*.oreequeg.com
Other domains in certificate