76/100 SECURITY SCORE

Certificate Information

Subject
CN=citizenwatch.uk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 02, 2025
Valid Until
March 02, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BB:CA:2E:D8:1A:84:2B:AF:D4:E8:B9:A6:D8:F3:A9:69:E6:34:6E:F2:EE:9B:15:34:32:72:70:47:B6:89:69:82
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
dubizzile.com *.dubizzile.com *.abudhabi.dubizzile.com *.admin.dubizzile.com *.api.dubizzile.com *.app.dubizzile.com *.backup.dubizzile.com *.beta.dubizzile.com *.bi.dubizzile.com *.blog.dubizzile.com *.chrome.dubizzile.com *.ci.dubizzile.com *.cpanel.dubizzile.com *.crm.dubizzile.com *.dashboards.dubizzile.com *.demo-insight.dubizzile.com *.demo.dubizzile.com *.dev.dubizzile.com *.dgw.dubizzile.com *.dns.dubizzile.com *.dubai.dubizzile.com *.flow.dubizzile.com *.forum.dubizzile.com *.forums.dubizzile.com *.help.dubizzile.com *.hostmaster.dubizzile.com *.insight.dubizzile.com *.m.dubizzile.com *.mx4.dubizzile.com *.mx7.dubizzile.com *.notexistsdev.dubizzile.com *.notexistsdgw.dubizzile.com *.ns1.dubizzile.com *.ns2.dubizzile.com *.old.dubizzile.com *.pop.dubizzile.com *.preview-viz.dubizzile.com *.prod-analytic.dubizzile.com *.report.dubizzile.com *.reporting.dubizzile.com *.shop.dubizzile.com *.store.dubizzile.com *.sup.dubizzile.com *.superset.dubizzile.com *.supersets.dubizzile.com *.temp.dubizzile.com *.test.dubizzile.com *.uae.dubizzile.com *.w.dubizzile.com *.workflow.dubizzile.com *.ww.dubizzile.com *.www.dubizzile.com

Other domains in certificate

15megasensa.com *.15megasensa.com *.agent.15megasensa.com
*.analytic.aprendeya.click aprendeya.click *.aprendeya.click *.insight.aprendeya.click *.qa.aprendeya.click *.superset.aprendeya.click *.www.aprendeya.click
barghestgiftsyork.co.uk *.barghestgiftsyork.co.uk *.dashboard.barghestgiftsyork.co.uk *.demo.barghestgiftsyork.co.uk *.insights.barghestgiftsyork.co.uk *.qa.barghestgiftsyork.co.uk *.reporting.barghestgiftsyork.co.uk *.test.barghestgiftsyork.co.uk *.visualizations.barghestgiftsyork.co.uk *.viz.barghestgiftsyork.co.uk *.ww38.barghestgiftsyork.co.uk
citizenwatch.uk *.citizenwatch.uk *.ww25.citizenwatch.uk
gregnoise.com *.gregnoise.com
houseofjonn.com *.houseofjonn.com *.ww16.houseofjonn.com
movistar.au *.movistar.au *.ww25.movistar.au
polkvoice.com *.polkvoice.com *.ufextension.polkvoice.com
*.random.singlechoicemovie.com singlechoicemovie.com *.singlechoicemovie.com