Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=cooloud.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 30, 2025
Valid Until
December 29, 2025
38 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F4:9A:68:74:96:87:E2:8D:6B:43:CB:45:7D:22:3D:FC:42:6A:BE:A2:76:5F:8D:29:EB:0C:22:94:5B:43:BE:BE
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
dikesoft.com
4andgo.com
www.ac-thing.com
www.alduin.com
development.amongus-tracker.com
amphoros.nl
privacypolicy.anrum.com
apartmentify.com
arki1.com
taquerialarosa.asap2go.com
alejmun.ashleyy.dev
fortuna.aszendit.com
www.avaitrust.com
www.awelcomewalk.com
bisuals.com
buzzly-ai.com
mg-oz.at.calculatorhub.app
admin-commandes.collectifensemble.com
cooloud.com
cooltallguy.com
music.cornel.su
cuddlycomforts.cc
damianbreland.com
darcydevelopment.com
denissantos.com
admin.distrito-panorama.com
doubletimesoftware.net
easy-flashcards.com
elegantspace.co
myaccountqa.elkenergy.com
enersystech.com
etisyn.app
www.etisyn.app
etisyn.com
eztags.ezcast.com
foodsygreenpak.com
friendtheory.com
v1.gaute.dev
www.geekcollector.app
www.getmicdrop.com
www.getmoon.app
winner.guru-pon.com
agents.honeylove.com
horlick.me
hyprcrit.com
admin.staging.icheckup.biz
idrisslatewala.me
iftar-time.com
igvalentine.com
joelalen.dev
johannarogers.com
joshuabruton.com
www.jscsoftarc.com
www.jyba.app
kindrel.com
kraigkeller.com
letsemjoy.app
lifeandlifebook.com
app.longshot.ai
ludonauts.com
machmacros.com
masbalon.com
mathegg.com
tread.matthewbeandev.com
www.migiude.org
finance.nemcrunchers.dev
nouyaku.app
auth.operator.app
powersaver.no
prosperai.tech
qanails-winder.com
rms.roscom.nl
fieldagent.sentera.com
sigmawars.com
sinewavetech.in
snap4fuze.com
solomonarnett.com
relookyourkitchen.speakylink.com
invite.streakmatch.com
data.stworzonedlafarmaceuty.pl
tatamatkabazaar.com
teambbs.in
www.thebig.deals
thetravellucky.com
www.thomasbutler.com
tickgoals.com
southampton.tieredtech.com
app.tiluchy.com
timpinetherapy.com
console.tokenhouse.dev
touch-less.dev
tribified.com
ubiforecast.com
uxroadmap.com
viajacomodo.com
www.visitour.com.au
nutrillo.waafi.ca
washmecleanlaundry.com
whilesoftware.com
xlsandblasting.com
Other domains in certificate