Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=web-admin.meraoffice.in
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 06, 2025
Valid Until
March 06, 2026
56 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B9:7F:23:FB:CC:06:D1:F7:25:4B:3F:BF:D6:64:D1:56:86:32:9C:3B:11:12:40:E9:BA:AF:8B:20:02:E4:65:FB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
backoffice.talent-alpha.com
308.industries
alligatorfest.org
anaphylaxiscst.altrixmedical.com
wa.aokitech.com.ar
dev.aurafemhealth.com
links.benbroadaway.org
www.bluelagoonpools.in
www.boothmanproperty.co.uk
www.cancun-excursions.net
chromatic.world
shoppers.shoppinglist.com.mt
compos.ai
www.cortexdynamics.in
dasperfekte.com
alphajarvis.dengun.com
docxel.com
technologiaaa.uem.edu.in
www.eservicii.com
app.factordecambio.es
dashboard.fairchain.org
gachatuku.com
www.dashboard.global360research.com
centralcoast.guesthouse.photography
www.hamburgueria294.com.br
contact.healthpointe.team
homescycle.com
honeyh.me
dashboard.idoc.idaho.gov
vote.ideafunding.org
iobot.fr
www.admin.jardimblauth.com.br
mars.joshuabennett.dev
dev.jotik.app
www.jp-ventures.de
staging.allmyhealth.league.dev
dev-auth.mapswipe.org
admin.marcefitness.com
www.mathpatterns.help
www.memurzam.com
web-admin.meraoffice.in
metarocx.com
www.mi-timesheet.com
p2p.micromal.net
www.mikekitchell.com
paradise.motionwave.studio
matt.mumau.dev
www.nanoprime.co.jp
mariner.advisor.netlaw.com
famille.opatry.net
www.ous.ma
ozhan.org
parttime.in
www.pawneeosagecasa.org
www.premiodispatch.com
app.promptparcelsja.com
strava-explorer.r42.ca
www.ra-ai.com
links.zoiabeta.razem.si
www.refyazilim.com
apps.regentsaustin.org
app.dev.retoriq.com
www.rftgdb.com
www.rio-ordershoes.com
sabor-a-peru.com
data.safemedicinedrop.com
www.saltsoftware.io
sanzen-tabi.com
scrapcfo.com
ease-beta.searchkings.ca
shreyandaanchal.com
labs.skydea.co
corporate.soelu.com
aida.stx.world
www.supremeventures.in
bodaparedesgaldamez.swanmoments.com
www.swiftcraft.tech
tailwindprefixer.com
tarsoit.org
et160.tcontur.pe
payment.tenplate.app
linkdev.theboxmarket.vn
bouganvilla.thediners.in
admin.thegrowthapp.org
theloganandcodyshow.com
treazur.com
tritan-medical-legacy.seacare.tritansoft.com
txtr.app
hazarigold.ulka.games
usenoto.com.br
villaeventincek.com
www.vinaydhomne.in
wastickerapps.info
whereispaulie.com
www.whitelightlabs.in
vinos.withmigo.com
goto.xnbay.com
cj-demo.yantralive.com
www.zamarilab.xyz
zamarilab.xyz
Other domains in certificate