Open
Cached
·
just now
93/100
SECURITY SCORE
Certificate Information
Subject
CN=auc.dk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
November 19, 2025
Valid Until
February 17, 2026
85 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BB:CB:1D:15:3F:21:42:F6:17:43:B5:51:08:8A:57:37:C1:37:00:34:EB:D7:0C:28:E9:81:BC:A1:43:B2:B4:CE
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15768000; includeSubdomains; preload;
Content-Security-Policy
Good
default-src; font-src; script-src; +7 more
default-src 'self' https://*.aau.dk https://*.azurewebsites.net https://*.dropbox.com https://*.dropboxusercontent.com https://podcastpusher.com https://*.doubleclick.net https://*.fonts.net https://*.linkedin.com https://*.facebook.com https://*.snapchat.com https://*.google.com https://*.youtube.com https://*.twitter.com https://*.survey-xact.dk https://*.microsoftonline.com https://*.office.com https://*.gstatic.com https://*.cookieinformation.com; font-src 'self' data: fonts.gstatic.com; script-src https://www.clarity.ms https://cxppusa1formui01cdnsa01-endpoint.azureedge.net/ https://www.clarity.ms/tag/n87ghf3gw4?ref=gtm2 https://www.googletagmanager.com/ https://www.youtube-nocookie.com 'self' 'unsafe-inline' https://*.scratcher.io https://*.elfsightcdn.com https://*.snapchat.com https://*.readpeak.com https://*.sc-static.net https://*.licdn.com https://*.google.com https://*.googleapis.com https://*.elfsight.com https://*.googletagmanager.com https://*.google-analytics.com https://*.facebook.net https://*.twitter.com https://*.cookieinformation.com https://*.youtube.com https://*.vimeo.com; connect-src https://dc.services.visualstudio.com https://widget-data.service.elfsight.com https://core.service.elfsight.com https://public-eur.mkt.dynamics.com https://cxppusa1formui01cdnsa01-endpoint.azureedge.net/ https://assets-eur.mkt.dynamics.com/ 'self' wss://aau-its-caai-shared-haandbog-prod.azurewebsites.net/ https://prod-aaudxp-vacancy-app.azurewebsites.net/ wss://aau-its-caai-studieservice-adgangstjek-prod.azurewebsites.net https://*.azurewebsites.net https://*.elfsightcdn.com https://*.aau.dk https://*.licdn.com https://*.linkedin.com https://*.google.com https://*.doubleclick.net https://*.snapchat.com https://*.oribi.io https://*.analytics.google.com https://*.googleapis.com https://*.elfsight.com https://*.google-analytics.com https://*.cookieinformation.com; img-src 'self' data: image/* https://*.aau.dk https://*.plan2learn.dk https://*.elfsight.com https://*.linkedin.com https://*.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.ivanenko.workers.dev https://*.taboola.com https://*.doubleclick.net https://*.adnxs.com https://*.readpeak.com https://*.google.dk https://*.gstatic.com https://*.dropbox.com https://*.dropboxusercontent.com https://*.google.com https://*.twimg.com https://*.facebook.com https://*.vimeocdn.com https://*.ytimg.com https://*.youtube.com https://*.googleapis.com https://*.elfsightcdn.com; frame-src https://kuula.co https://madsheiselberg.github.io https://copilotstudio.preview.microsoft.com https://login.windows.net https://login.windows.net/ https://aaublanketterdev.powerappsportals.com/ http://mfc-print03.aau.dk https://assets-eur.mkt.dynamics.com/ https://www.clarity.ms https://serviceinfo.dk 'self' https://www.youtube-nocookie.com/ https://www.googletagmanager.com/ https://public-eur.mkt.dynamics.com https://*.geckobooking.dk https://*.powerapps.com https://*.cobe.dk https://*.powerbi.com https://*.scratcher.io https://*.youtube.com https://*.plandisc.com https://*.moodle.aau.dk https://*.matterport.com https://*.microsoftonline.com https://*.360company.dk https://*.snapchat.com https://*.doubleclick.net https://*.spotify.com https://*.google.com https://*.vercel.app https://*.serviceinfo.dk https://*.libraryh3lp.com https://*.aau.dk https://*.facebook.com https://*.survey-xact.dk *.svc.dynamics.com https://*.office.com https://*.kuula.co https://*.cookieinformation.com https://*.vimeo.com; style-src 'self' 'unsafe-inline' https://*.google.com https://*.googleapis.com; base-uri 'self'; form-action 'self' https://*.facebook.com; frame-ancestors 'none';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
no-referrer, strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports