Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=mahoro.jp
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 11, 2025
Valid Until
February 09, 2026
87 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3A:1F:99:28:D0:37:35:2B:00:D9:2C:64:F2:B0:FA:24:1A:48:CF:1D:52:AF:02:07:B1:B6:9B:E6:61:02:25:F5
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
conquisevent.app
stage.2u.fan
64keys.cz
agenio.app
www.agristorz.com
aiteruchat.net
alexandergaribello.com
www.alinkeo.com
www.all-city.app
apexloanpartners.com
cardapioweb.agiledelivery.app.br
www.arsipvirtual.com
atlasbay.site
baseval.com
bgcmanila.com
www.bilindgame.com
tribuds.bindebank.com
www.blackstarlegalservices.com
auth.blankmap.app
blokkiti.com
app.dev.bluevis.io
bookbloom.app
www.boyjones.org
btcum.com
test-business.buzztop.io
gg.caarya.cloud
app.certified-identity.com
smart-health-test.ssd.co.ke
marumedia.co.kr
coachwallah.com
codecontrol.app
tv.coibong88.me
prom-opecs.com.ua
cscservizi.it
dvankooijk.app
entrusy.com
lanahub.enzodias.com.br
biff.findka.com
www.fix.claims
chimera.fortneyengineering.com
www.funyiraskomarom.hu
uat.getwallet.cards
globalize.io
gmovillsdehidalgo.com.mx
grandtrain.ch
herosmarketing.digital
www.hwcoin.org
iabrmv.com
www.iabrmv.com
www.ilest.app
imark.plus
kiddolearn.app
left-over.eu
apply.lima.capital
gamers-graphics.lloydborres.com
app.locade.app
app.lpaes.ovh
mahoro.jp
dessertpalace.megapos.store
megs-out.co
minders.app
quiz-mx.moonsdental.ninja
multiaibot.com
my-ci.app
ibadahapp.my.id
mybeo.rs
shipment.myshoprime.in
naijahustleplug.com
nrdomain.com
admin.paiementloxam.fr
pdcgsolutions.com
plancknetwork.com
point-speedlogistics.cloud
www.pomoclock.xyz
quizgrade.online
radiantech.io
docs.rosepetal.ai
home.samr.app
securesign.fi
www.sparkyslogistics.com
sstcolombia.com
starhelp.click
auth.summoningstone.app
terilastech.com
informs.terracat.co.nz
thecloudhosters.com
www.thedare.org
tnfboxes.us
travelgenie.tours
app.tripsik.com
turtlewithcrocs.com
underkover.in
valet-ai.com
my.vanityplanet.com
facility-test.voltie.us
music.warma.lol
support.wecommend.app
wingcruit.com
xaydungtt.com
yoilog.app
Other domains in certificate