76/100 SECURITY SCORE

Certificate Information

Subject
CN=watersecureco.com.au
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026 73 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
07:BB:E1:68:70:9D:A3:F7:F3:9D:83:EA:D3:99:F3:9E:4E:23:62:07:DA:F3:52:9F:46:63:D9:F3:E1:50:BF:B8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
artstorecafe.com *.artstorecafe.com *.sitemap.artstorecafe.com *.ww16.artstorecafe.com

Other domains in certificate

alburaqpay.com *.alburaqpay.com *.rd.alburaqpay.com
amercanfirstfinance.com *.amercanfirstfinance.com *.demo.amercanfirstfinance.com *.hostmaster.amercanfirstfinance.com *.mysql04.amercanfirstfinance.com
*.admin.cocoeats.co.uk *.app.cocoeats.co.uk cocoeats.co.uk *.cocoeats.co.uk *.manage.cocoeats.co.uk *.server.cocoeats.co.uk
dam.com.pl *.dam.com.pl *.mail.dam.com.pl *.store.dam.com.pl *.webmail.dam.com.pl *.www.dam.com.pl
costs.it *.costs.it *.s.costs.it
*.2024x.desy.it desy.it *.desy.it *.givadev.desy.it
*.amedd.elifoaghaistou.com *.avatars.elifoaghaistou.com *.blog.elifoaghaistou.com elifoaghaistou.com *.elifoaghaistou.com
*.bav.msglive.com *.intra.msglive.com msglive.com *.msglive.com *.officevpn.msglive.com *.rds1.msglive.com *.remoteaccess.msglive.com *.sslvpn2.msglive.com *.webvpn.msglive.com
narmadaexports.co *.narmadaexports.co *.ww16.narmadaexports.co *.ww25.narmadaexports.co *.ww38.narmadaexports.co
offensivesecrity.com *.offensivesecrity.com *.ww38.offensivesecrity.com
*.admin.rule33.xyz rule33.xyz *.rule33.xyz *.ww1.rule33.xyz *.ww2.rule33.xyz *.ww25.rule33.xyz
*.academy.segura.com *.antoine.segura.com *.conexion.segura.com *.cril.segura.com *.deb.segura.com *.flota.segura.com *.loja.segura.com *.panvpn.segura.com segura.com *.segura.com *.suppport.segura.com
ultracine.com.br *.ultracine.com.br *.ww38.ultracine.com.br
*.account.voxly.io *.ci.voxly.io *.dev.voxly.io *.hostmaster.voxly.io *.prod.voxly.io *.registry.voxly.io *.relay.voxly.io *.server.voxly.io voxly.io *.voxly.io *.www.voxly.io
*.news.watersecureco.com.au *.save.watersecureco.com.au *.superset.watersecureco.com.au watersecureco.com.au *.watersecureco.com.au