Open
Cached
·
just now
89/100
SECURITY SCORE
Certificate Information
Subject
CN=*.charlestonroadregistry.com
Issuer
C=US, O=Google Trust Services, CN=WR2
Valid From
October 13, 2025
Valid Until
January 05, 2026
60 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
39:9C:5B:9C:FD:D3:65:88:98:BF:03:37:BC:A4:DE:D4:3A:15:CC:E5:A9:53:82:44:A5:C4:7B:04:80:16:37:51
Alternative Names
Security Configuration
TLS Protocols
TLS 1.0
TLS 1.1
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
Warnings
- • TLS 1.1 is deprecated and should be disabled
- • TLS 1.0 is deprecated and should be disabled
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
script-src; object-src; report-uri; +1 more
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
- • Consider adding 'issuewild' records to control wildcard certificate issuance
Subject Alternative Names
106 domains
crr.com
*.crr.com
bar.foo
*.bar.foo
charlestonroadregistry.com
*.charlestonroadregistry.com
googleregistry.co
*.googleregistry.co
nic.ads
*.nic.ads
nic.android
*.nic.android
nic.app
*.nic.app
nic.boo
*.nic.boo
nic.cal
*.nic.cal
nic.channel
*.nic.channel
nic.chrome
*.nic.chrome
nic.dad
*.nic.dad
nic.day
*.nic.day
nic.dclk
*.nic.dclk
nic.dev
*.nic.dev
nic.docs
*.nic.docs
nic.drive
*.nic.drive
nic.eat
*.nic.eat
nic.esq
*.nic.esq
nic.fly
*.nic.fly
nic.foo
*.nic.foo
nic.gbiz
*.nic.gbiz
nic.gle
*.nic.gle
nic.gmail
*.nic.gmail
nic.goog
*.nic.goog
nic.google
*.nic.google
nic.guge
*.nic.guge
nic.hangout
*.nic.hangout
nic.here
*.nic.here
nic.how
*.nic.how
nic.ing
*.nic.ing
nic.map
*.nic.map
nic.meet
*.nic.meet
nic.meme
*.nic.meme
nic.mov
*.nic.mov
nic.new
*.nic.new
nic.nexus
*.nic.nexus
nic.page
*.nic.page
nic.phd
*.nic.phd
nic.play
*.nic.play
nic.prod
*.nic.prod
nic.prof
*.nic.prof
nic.rsvp
*.nic.rsvp
nic.search
*.nic.search
nic.soy
*.nic.soy
nic.xn--flw351e
*.nic.xn--flw351e
nic.xn--q9jyb4c
*.nic.xn--q9jyb4c
nic.xn--qcka1pmc
*.nic.xn--qcka1pmc
nic.youtube
*.nic.youtube
nic.zip
*.nic.zip
epp.registry-qa.google
whois.registry-qa.google
epp.registry-sandbox.google
whois.registry-sandbox.google
epp.registry.google
whois.registry.google
Other domains in certificate