77/100 SECURITY SCORE

Certificate Information

Subject
CN=admin.mestr.no
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 21, 2025
Valid Until
February 20, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
52:D0:DF:22:DD:68:76:9F:E8:20:20:A3:A5:31:B6:78:38:14:3D:AE:C9:20:11:60:4A:72:4E:B2:72:01:BA:4E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
arcade.matthewpaulin.com

Other domains in certificate

antirracistas.99jobs.com
o.aabass.net
aguasan.ch
www.alexmcneil.net
www.andemta-exhibitions.com
web.araucofoodie.cl
soteria.arcanio.com
dev.ayeq.io
joe.bandenburg.com
www.battle.online
www.bebnista.pl
www.jayatama.biz.id
bizzysrl.it
brewlandowizards.com
cartoons-in-lockdown.nl
influencer.casting-asia.com
cyber-lane.se
notes.darkdown.io
www.dnahomes.me
llms.dugward.com
tracker.duyet.net
eclisy.com
www.electricbikesexperts.co.uk
www.enutri.app
eventsethiopia.com
everyonecanread.org
favn.com
app-grj.flexitechtravel.com
foripo.org
www.formgroup.io
getbrainnotes.com
www.getspect.app
godplan.dk
www.grouptrac.com
growthdiary.blog
haltogame.com
handyone.co.za
happy-birthday-heysu.com
hetverwendenestje.be
firebase.np-sc-yard-management.gcp.homedepot.com
hypehq.io
www.imgvue.com
impacthorizon.io
web.appsinpolsc.infobrcorp.com.br
www.innobitsoftware.com
login.intuitionrobotics.com
sb.ivankana.com
janeschmidt.dk
alcoholzelftest.jellinek.nl
events.joinblynk.com
josemalpe.dev
www.justappin.com
www.kaneleuc.com
app.khelovani.com
labiciadventures.com
lasvengeancecrew.com
sn.lightone.dev
www.maison.app
manylogue.com
admin.mestr.no
www.metashark.llc
mistrasportal.com
mysterysign.com
portal.mzonehealth.com
welcome.dev.novafutur.com
www.ocbeachwax.com
petermezes.sk
www.picspots.com
analisis-frekuensi.thedev.pp.ua
pricestock.com
horne-fl-dev.psg-labs.com
risepower.yoga
www.robinboldt.de
rootprotocols.io
www.termsheet.sdg-investments.com
www.sevision.in
dashboard.staging.side-hr.com
sofiadonovan.com
songchaeyoung.com
www.sushichefllucmajor.es
www.tamilnaducalltaxi.com
bizops.int.tcat.app
www.thewshopclub.com
www.train121.app
trapcat.com
trevormart.in
bio.uiclap.com
upstairs.jewelry
upthepadel.com
deqspills.dev.utah.gov
vendas.vendergas.com.br
www.verisku.com
www.css.vyeron.com
srmgrtracker.wearetnv.com
www.whocan.org
www.wink.online
wishtech.io
h.wkt.wiki
www.yellowspyglass.com