Open
Cached
·
just now
80/100
SECURITY SCORE
Certificate Information
Subject
CN=www.ellindero.es
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 08, 2025
Valid Until
March 08, 2026
55 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1E:52:4D:CF:BD:E2:EB:0E:D1:1E:1B:A1:AF:A7:12:DE:B7:C0:BE:1B:15:53:29:8D:19:F8:15:F3:0B:C8:76:7D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Wildcard CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 6 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
Subject Alternative Names
100 domains
countsbook.com
recruiters-staging.acelr8.com
wwww.adrian-c-louis.com
airsupport.group
allianzbyamanbareng.com
drishti.aolic.in
apidash.dev
www.apomap.app
www.awovenworld.com
api.beaconoms.com
ldp.beacons-npa.gov.uk
bednarz.design
www.castlebook.com
qa.cloudroutine.com
beachcam.co.il
freunddteportal.bitworks.com.sv
concepviz.in
cosmodrome.dev
www.countylinebluegrass.com
the-hangman-app.danielq.dev
auth.decorum.work
verkeersveiligheid-uat.dokdata.nl
inreuma.telemedicina.drtis.com.br
easypayapp.easypay.sa
www.ellindero.es
shoot.nerf.emallstudio.com
fingerscrossedapp.com
superdash.flutter.dev
flyproductionhouse.com
futureleisurefoundation.com
g-immobilier.com
www.gcnym.com
www.glowfishproductstudio.com
gneventrental.com
gordonchen.dev
tamlinh.io.vn
app.staging.jahezacademy.com
www-qa.jimsformalwear.com
john-walker.co.uk
jointrst.com.br
www.jtc-kaitori.jp
experiment-app.kiwi-go.jp
dev-share.konaiceboost.com
startup.kspu.edu
kyleg.dev
app.layer.team
www.lucidstreamer.com
dash.lumedeodorant.com
www.luxuriafinvest.com
app.mapkid.info
mecomdubai.com
www.megorder.com
inventory-management.merkle.dev
www.laa.mightybyte.us
uat.mkplabs.com
download.ml.fitness
www.mtrfreight.com
www.myquickqr.com
www.mytruckingcalculator.com
www.nahuelbutarollerangol.cl
metacricket360.ncinga.ai
tools.neverdontplay.com
ngutrailblazerclub.com
www.novaquach.com
www.nyirweld.hu
covid-screening.oakwoodfriends.org
play.on-replay.com
app.onrech.at
ourfaithdoon.org
www.pammagotchi.com
pawpawdot.life
www.peliscope.com
www.physhead.com
kzinandhtet.piticommerce.com
platinumcouchproductions.com
praneshsaran.com
primeoneluxe.com
purzey.com
ra-vilmar.de
releasetask.com
safeairsafeschools.ca
sastrala.id
scanyourmacros.com
setuplibrary.com
shadowsoftheafterland.com
simplegoaltracker.com
www.app.skorebrd.com
cms-staging.smartplanthome.com
emathstudio.snapmentor.no
www.swiftbee.co.uk
basometro-develop.taniafruchi.com.br
tayloratodd.com
color-swatches.tbun.dev
thehippoisfat.com
theunofficial.space
www.tugranja.com.co
warenex.com
tools.wargdrones.com
www.whiteoakrenovation.net
www.zirostudio.com
Other domains in certificate