91/100 SECURITY SCORE

Certificate Information

Subject
CN=vintagebridaljewellery.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 17, 2026
Valid Until
August 15, 2026 80 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
17:E6:0A:63:61:92:D3:66:20:FF:2C:2F:91:69:C8:6F:0B:0F:A4:A3:62:04:44:C2:7D:66:0D:89:2F:68:32:8D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin
Permissions-Policy
Present
geolocation=(), midi=(), sync-xhr=(); +6 more
Recommendations
  • Add Content-Security-Policy header to prevent XSS attacks

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
that.school *.that.school *.adminer.that.school *.and.that.school *.autodiscover.that.school *.classes.that.school *.hs2.that.school *.m.that.school *.mail.that.school *.msk.that.school *.sitemap.that.school

Other domains in certificate

cabbage.au *.cabbage.au
*.amg.dalesrestaurant.net *.antivirus.dalesrestaurant.net *.api.dalesrestaurant.net *.au-portal-partner.dalesrestaurant.net *.beta.dalesrestaurant.net *.bi.dalesrestaurant.net *.chat.dalesrestaurant.net *.ci.dalesrestaurant.net dalesrestaurant.net *.dalesrestaurant.net *.dev.dalesrestaurant.net *.development.dalesrestaurant.net *.ezproxy.dalesrestaurant.net *.flowiseai.dalesrestaurant.net *.hereweb.dalesrestaurant.net *.integration.dalesrestaurant.net *.ofertas-trabajo.dalesrestaurant.net *.pdgn2.dalesrestaurant.net *.pipeline.dalesrestaurant.net *.prod.dalesrestaurant.net *.psb.dalesrestaurant.net *.staging.dalesrestaurant.net *.steinhardt.dalesrestaurant.net *.trabajo.dalesrestaurant.net *.uat.dalesrestaurant.net
indojavstream.site *.indojavstream.site
khalidji.online *.khalidji.online
khan-goch.de *.khan-goch.de
khanyounis.store *.khanyounis.store
kiraskys.online *.kiraskys.online
kwuu83.icu *.kwuu83.icu
link1-seributoto.online *.link1-seributoto.online
*.255infjd.lv111.cn *.96138.lv111.cn *.dr733.lv111.cn *.ek.lv111.cn *.gn5vzx.lv111.cn *.k.lv111.cn *.kqxul.lv111.cn lv111.cn *.lv111.cn *.m.lv111.cn *.nkqxul.lv111.cn *.sdr733.lv111.cn *.wwww.lv111.cn *.xfdsgq.lv111.cn *.yiqdm.lv111.cn
materiahoje-nova.online *.materiahoje-nova.online
matiztechz.online *.matiztechz.online
maxplay303mvp.store *.maxplay303mvp.store
mcdonalds-reichenbach.de *.mcdonalds-reichenbach.de
mcity.fun *.mcity.fun
*.mail.murphybusinessselling.com murphybusinessselling.com *.murphybusinessselling.com
*.app.radioworld66.com *.connect.radioworld66.com *.m.radioworld66.com radioworld66.com *.radioworld66.com *.youla.radioworld66.com
unleaded.au *.unleaded.au
vintagebridaljewellery.co.uk *.vintagebridaljewellery.co.uk