77/100 SECURITY SCORE

Certificate Information

Subject
CN=tomfliz.pl
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 29, 2025
Valid Until
January 27, 2026 53 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E3:5F:26:90:6D:5E:F3:32:A0:EB:AD:15:FD:54:AB:B1:FA:55:BE:57:A7:87:52:69:3B:6C:71:28:CE:6A:72:FA
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
demo-intranet.goyazi.com

Other domains in certificate

admissions.kusip.ac.th
accessinternationalstudies.com
adammichelin.dev
aidara.app
auth.askcenter.com
link.aura.com
www.azizaismail.com
bigmach.in
staging.bluerobot.com
bonbazou.ca
www.botlabs.co.uk
panel.botsedge.com
www.bracelit.es
blog.byteqube.com
calfropingdaily.com
links.canvidapp.com
backpack.ccpcs.org
typespeed.cdcdisdiksulsel.info
www.christianviglianisi.com
app.property.co.id
reporting-staging.carclub.com.sg
meka-tech.com.tr www.meka-tech.com.tr
www.donhotel.com.uy
www.contracts.plus
danapravim.com
fairtree.dataviewfund.com
deepflow.kr
staging.diaplatform.app
app.docmorris.de
web-staging.doyumeibo.jp
www.drgopalsharma.com
www.ervanrenault.com
evtn.co.jp
extradimension.games
admin.foreverware.org
reseller-demo.geoservice24.com
robert.glaz.dev
glomo.no
develop.gobertha.com
www.gooseclip.com
grainfrastructure.com
pztw.haohows.com
visite.hausvalet.ca
blog.hotcocoasoftware.com
www.cekulis.id.lv
open.inyourarea.co.uk
konguassociation.com
www.koolkid.vn
www.kopiev.studio
www.lenormandapp.com
lexicount.in
form.litta.co
mariadelrosariogarcia.com
www.mctech-service.com.mx
www.mdotnews.com
api.mindburp.se
invite.dev.imagine-impact.mindklab.com
www.minervia.ai
monitor2move.dk
pilot-galaxy.mosaicapp.com
widerlov.demo.movello.se
mypetvetonline.ca
safety.newtn.life
www.nudgegram.com
test.dev.nyle.ai
www.oakay.com
odaiwa.com
ogpanic.com
www.opriori.com
packtrack.io
www.pensioenbijarseuslab.nl
merch.proxyteng.nl
realityworkshop.design
redoxdesignx.com
cps-dev.refactory.digital
www.registrdluzniku.info
ardac.rflex.io
www.rx7method.com
samosirco.com
www.schabla.com.br
ll.sctindia.in
seasonstaff.de
snapmentor.no
www.sttammanyrepublicans.org
tapedin.net
tcgnotify.net
tec-craft.com
ticsocialsas.com
tomfliz.pl
staging.towpro.io
trapmafiaoficial.com
trycoup.com
dhp.check-in.thrive.uk.com
umair.dev
www.vizulr.com
house.webmodell.no
whiteout-climbing.com
yvrshufflers.com