Open
Cached
·
4h ago
77/100
SECURITY SCORE
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
January 07, 2026
Valid Until
April 07, 2026
85 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
C8:29:99:30:E5:B2:BD:01:0F:3D:5F:DB:00:FA:8C:49:E6:22:7E:69:62:18:CB:C1:90:F4:E7:2D:2D:28:B8:8D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
47 domains
byrumfisk.com
aurallpianotuning.com
www.aurallpianotuning.com
tls.automattic.com
hairstylescare.car.blog
www.hairstylescare.car.blog
ledgestonediscgolf.code.blog
www.ledgestonediscgolf.code.blog
creationsdaure.fr
www.creationsdaure.fr
cvecezla.com
www.cvecezla.com
innerthoughts281484096.com
www.innerthoughts281484096.com
www.rookie-chef.com
rootmolen.be
www.rootmolen.be
www.rorykramer.net
sweetsurprise.blog
www.thehayyan.id
thepaintedcabinetllc.com
thepurpleorchid.blog
thereticentprisoner.com
theseasideoflife.com
www.thesinglegirlexperiment.com
tidwelltidbits.com
timestreamguide.com
timharnesstravels.com
toshmcintosh.com
www.toshmcintosh.com
www.trail-criu.com
www.transfigurationlutheranchurch.org
www.truelucky2019gmail.com
utmoee.com
vagabondtexan.com
verdidevelopments.com
www.verdidevelopments.com
www.verus-cares.org
vincentessadeq.com
www.vincentessadeq.com
aquaesk.water.blog
weekendinmilwaukee.blog
wiltahwa.com
www.wiltahwa.com
www.wodobo.ai
www.yogaaran.com
yogaaran.com
Other domains in certificate