Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=tint.cafe
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 08, 2025
Valid Until
January 06, 2026
56 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
32:39:A4:DE:E5:74:8F:B4:BA:1C:51:57:63:9C:7D:07:55:D7:DA:34:FD:D8:0F:BA:EC:BD:4C:70:F1:AE:CE:FA
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
delisles.com
www.1tuner.com
my.abracadalo.com
dev5007.academap.com
contact.adxsdk.com
www.aelab.my
afdi.de
raboag.aghedgedesk.com
upload.amkmicrofinance.com
angjinsheng.com
connect.articad.com
www.auvaan.com
backslashlinux.com
credenciados-botafogo.bepass.com.br
sso-dev.betasi.pl
admin.bizgeek.in
manager.brewbill.com
staging.manager.brewbill.com
truck.brightq.com
uat-ops.campayna.com
cartwinks.com
www.chls.me
www.cloudappit.com
demo.test.cloudschool.org
coaxdes.com
codeforfun.com
mw.creditea.mx
www.dcpsaude.com.br
dynna.me
pls.aiu.edu.my
www.ever-nest.de
www.fidelidadesotreq.com.br
www.geo-training.at
app-v2.getfluence.com
memberapp.gmiclub.tech
tryreact.goibniudesign.com
www.grizzlycomputing.com
app.hazira.com
tinnibot.hearingpower.co
www.helsingfors-vanda.fi
staging.hotelreservation.expert
warikan.tool.icchi.me
qa.idealcareerpath.com
idesignshop.online
www.ininfinite.com
stg.innovators-career.com
admin.jidlonatrek.cz
www.jonnygonzalez.dev
cocomo.justbit.it
www.k-y.win
keyaccountmanagementtraining.ie
musicvisualiser.kieranparanjpe.com
kkgv.net
klimentowicz.com
lasthopeguild.com
mertgurer.com
michaelbakerportfolio.com
skeppsholmen.demo.movello.se
www.mstconline.com
mudanzasonline.net
mylastsunday.com
pic-win2day.mentor.neccton.com
elt.cns.net.tw
nhahangmaisonvie.com
testflight.oensan.com
osdifa.com
ipfsgateway.ownerfy.com
www.piletivahetus.ee
populartradelinks.com
psgltech.com
install.publigo.app
asogans-admin.pujasweb.co
www.reinholtzresearch.com
rhagil.com.br
www.rymcd.xyz
www.sagemanufacturingindia.com
columbus.scouthub.app
secondmentor.com
moj.semilac.pl
senior-living-tips.com
sharetuk.com
shtm-dv.site
survey.smaki-maki.com
www.smartkeyplatform.io
dev.spellbinder.co
bodacivilbarahonacastillo.swanmoments.com
play.taptapwin.co
theonewaytaxi.in
my.timesheet.io
tint.cafe
ielts.tretrau.vn
valenreyesnutricion.com
www.vatrox.com
villamadonnadelbagno.com
closet.vitanewstetter.com
app.wotimo.com
wrship.io
www.yollevotuscosas.com
yutaok.com
eli5.zksync.io
Other domains in certificate