Open
Cached
·
just now
93/100
SECURITY SCORE
Certificate Information
Subject
CN=dev.re-leased.com
Issuer
C=US, O=DigiCert, Inc., CN=GeoTrust Global TLS RSA4096 SHA256 2022 CA1
Valid From
November 15, 2025
Valid Until
April 14, 2026
90 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A6:F1:4E:80:0B:C5:9D:B4:9A:1A:41:55:53:18:08:1D:FC:C9:87:E0:59:36:F0:45:C2:06:CE:60:E4:2F:A6:64
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +6 more
default-src 'self' blob: *.webspellchecker.net *.zdassets.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.re-leased.com *.googleapis.com *.gstatic.com *.google-analytics.com *.googletagmanager.com browser-update.org *.vo.msecnd.net *.azurefd.net *.webspellchecker.net *.raygun.io *.ggpht.com app.pendo.io pendo-io-static.storage.googleapis.com cdn.pendo.io pendo-static-5738132835926016.storage.googleapis.com data.pendo.io assets.calendly.com *.announcekit.app announcekit.co static.zdassets.com re-leasedsupport.zendesk.com js.monitor.azure.com static.asknice.ly cdn.asknice.ly released.asknice.ly; style-src 'self' 'unsafe-inline' *.re-leased.com *.googleapis.com *.vo.msecnd.net *.azurefd.net *.bootstrapcdn.com *.ggpht.com svc.webspellchecker.net app.pendo.io cdn.pendo.io pendo-static-5738132835926016.storage.googleapis.com *.announcekit.app static.asknice.ly cdn.asknice.ly released.asknice.ly; img-src 'self' *.re-leased.com data: *.googleapis.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.vo.msecnd.net *.azurefd.net *.webspellchecker.net *.ggpht.com cdn.pendo.io app.pendo.io pendo-static-5738132835926016.storage.googleapis.com data.pendo.io re-leased-help.zendesk.com re-leasedsupport.zendesk.com static.asknice.ly cdn.asknice.ly released.asknice.ly; font-src 'self' data: *.gstatic.com *.vo.msecnd.net *.azurefd.net *.bootstrapcdn.com svc.webspellchecker.net *.re-leased.com; connect-src 'self' *.googleapis.com *.google-analytics.com *.raygun.io *.services.visualstudio.com svc.webspellchecker.net app.pendo.io data.pendo.io pendo-static-5738132835926016.storage.googleapis.com static.asknice.ly cdn.asknice.ly released.asknice.ly app-released-prodglobal-prizmdocviewer-apac.azurewebsites.net app-released-prodglobal-prizmdocviewer-us.azurewebsites.net app-released-prodglobal-prizmdocviewer-uk.azurewebsites.net wss: *.re-leased.com *.service.signalr.net *.zdassets.com re-leased-help.zendesk.com https://id.zopim.com vm-prodglobal-docker-apac-00.australiaeast.cloudapp.azure.com *.monitor.azure.com *.applicationinsights.azure.com *.azurefd.net; frame-ancestors 'self' app.pendo.io; child-src 'self' app.pendo.io static.asknice.ly cdn.asknice.ly released.asknice.ly *.youtube.com *.figma.com calendly.com announcekit.co https://analytics.crediaexecutive.com https://insights.re-leased.com; frame-src 'self' blob: *.re-leased.com app.pendo.io static.asknice.ly cdn.asknice.ly released.asknice.ly *.youtube.com *.figma.com calendly.com announcekit.co https://analytics.crediaexecutive.com https://insights.re-leased.com re-leased.sbx.keylight.com
X-Frame-Options
Good
SameOrigin
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), gyroscope=(), magnetometer=(), midi=(), payment=(), usb=(), serial=(), hid=(), bluetooth=(), xr-spatial-tracking=()
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports