Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=quicklink.ambii.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 08, 2025
Valid Until
January 07, 2026
52 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B3:99:31:1F:73:13:1E:27:1D:6D:98:E6:A7:3A:3C:90:89:82:8B:02:F9:09:B6:91:20:9A:F5:A3:A2:B8:B3:39
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
cambrianprotocol.com
308.industries
agrimatco.hr
alligatorfest.org
quicklink.ambii.com
ayurvedickendra.com
beardsandfur.com
payments.beereaders.com
www.bernavemutlu.com
analyticus.bestpointwebdesign.com
www.blackhillonline.com
www.bluelagoonpools.in
www.boothmanproperty.co.uk
storybook.btdevs.com
apply.burialinsurancequote.com
www.cancun-excursions.net
www.capetipestates.com
chengzhi-wang.com
chizu-quest.com
gs.claytonjacobs.dev
musatec.com.ec
shoppers.shoppinglist.com.mt
company-locator.com
conwaycleaningmn.com
csinterns.com
dasperfekte.com
decoderesolvency.com
app.deepbv.nl
deluxebucak.com
eganlegacypartners.com
www.eservicii.com
eventful-app.com
fishermandirect.com
app.fiters.co
gachatuku.com
my.getkisi.com
gilroydigital.com
www.dashboard.global360research.com
centralcoast.guesthouse.photography
www.hanspaulskestavitelstvi.cz
auth.icepeak.ai
dashboard.idoc.idaho.gov
vote.ideafunding.org
chat-stage.ischoolconnect.com
itsallno.de
xushs-equinox.jameventsph.com
www.keystonecrusades.com
staging.allmyhealth.league.dev
book.litta.co
dady.lupi.delivery
malikawawer.com
dev-auth.mapswipe.org
admin.marcefitness.com
maxmartynov.com
www.memurzam.com
web-admin.meraoffice.in
aula.metodoconsultores.cl
p2p.micromal.net
www.minoekonomi.com
www.mlnkv.com
matt.mumau.dev
musica-linguae.ru
mariner.advisor.netlaw.com
famille.opatry.net
ozhan.org
parttime.in
passionlocker.de
www.pedakon.fi
strava-explorer.r42.ca
www.reflectly.app
www.refyazilim.com
apps.regentsaustin.org
www.saltsoftware.io
app-packages.staging.shopdit.com
www.shotlytics.com
prototype-testing.skyixd.com
snapapps.ai
stylecuv.com
www.supremeventures.in
tailwindprefixer.com
tarsoit.org
tecalis.com
www.terinyglobal.com
www.the-three.com
bouganvilla.thediners.in
thepaymentbutton.com
stg.thermolog.biz
www.thincera.com
hazarigold.ulka.games
usenoto.com.br
b12.vexpets.com
www.vinaydhomne.in
vishalsaini.dev
wastickerapps.info
www.willowisp.ca
www.x-pr.co
goto.xnbay.com
cj-demo.yantralive.com
www.z0.nu
consumer.zeaeye.com
Other domains in certificate