Open
Cached
·
just now
83/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=stamps.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 01, 2026
Valid Until
June 30, 2026
53 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:98:9A:F4:1D:6D:1E:71:1F:4E:09:1A:9A:51:C5:01:E0:BC:A6:ED:32:B3:42:92:EF:84:06:8B:68:4C:2C:63
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
geolocation=(), midi=(), microphone=(); +5 more
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
70 domains
account.endicia.com
content.endicia.com
developer.endicia.com
label.endicia.com
print.endicia.com
registration.endicia.com
swsim.endicia.com
testing.endicia.com
www.endicia.com
account.web.endicia.com
accountext.qasc.endicia.com
developer.testing.endicia.com
history.web.endicia.com
print.testing.endicia.com
print2.testing.endicia.com
registration.staging.endicia.com
registration.testing.endicia.com
www.qa004.endicia.com
www.stage.endicia.com
account.web.testing.endicia.com
api.prd.goglobalpost.com
api.stg.goglobalpost.com
dev.goglobalpost.com
portal.goglobalpost.com
postage.internetpostage.com
postage.staging.internetpostage.com
us.mytracking.net
api.shippingeasy.com
app.shippingeasy.com
slush.shippingeasy.com
staging.shippingeasy.com
registration.shipworks.com
registration.staging.shipworks.com
account.web.stamps.com
account.web.testing.stamps.com
app.web.stamps.com
content.stamps.com
content.testing.stamps.com
history.web.stamps.com
login.testing.stamps.com
print.stamps.com
print.testing.stamps.com
print2.stamps.com
print2.testing.stamps.com
registration.qa001.stamps.com
registration.qa004.stamps.com
registration.stamps.com
sdcwebsite.dev.stamps.com
sdcwebsite.staging.stamps.com
signin.qa002.stamps.com
staging-registration.stamps.com
stamps.com
stm-api.dev02.stamps.com
stm-api.stamps.com
stm-api.testing.stamps.com
swsim.stamps.com
swsim.testing.stamps.com
testing.stamps.com
webpostage.stamps.com
wp.stamps.com
www.stamps.com
usps.stampsendicia.net
uspsportal.staging.stampsendicia.net
admin.testaspen.com
api.testaspen.com
platform.testaspen.com
devportal.stg.yourglobalpost.com
public.prd.yourglobalpost.com
public.stg.yourglobalpost.com
ssportal.stg.yourglobalpost.com
Other domains in certificate