79/100 SECURITY SCORE

Certificate Information

Subject
CN=tonantzinpreschool.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 06, 2026
Valid Until
May 07, 2026 81 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7B:80:20:75:DF:36:00:10:4E:CB:A8:E4:72:7C:A4:96:74:9D:67:36:3C:1F:78:95:63:9B:A8:B0:70:61:28:64
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
virginrobot.cam *.virginrobot.cam

Other domains in certificate

tonantzinpreschool.org *.tonantzinpreschool.org
topstudiodev.com *.topstudiodev.com
toronto-accident-287027461.click *.toronto-accident-287027461.click
touchstone.love *.touchstone.love
tourline.net *.tourline.net
tqmnsg.pro *.tqmnsg.pro
tradersview.in *.tradersview.in
transformcorefitness.run *.transformcorefitness.run
trendio.ltd *.trendio.ltd
true--haven.com *.true--haven.com
truedigital.website *.truedigital.website
trueheart.love *.trueheart.love
trueupnorthtop.com *.trueupnorthtop.com
trynextgensalesteam.com *.trynextgensalesteam.com
ttgrr.bid *.ttgrr.bid
tuk-shop.com *.tuk-shop.com
tvojekreativa.site *.tvojekreativa.site
twslive.vip *.twslive.vip
tyrrz.gdn *.tyrrz.gdn
ufosightings.love *.ufosightings.love
ux78s.top *.ux78s.top
v345n4.top *.v345n4.top
v6d3.buzz *.v6d3.buzz
valentinecat.com *.valentinecat.com
valentino7.com *.valentino7.com
vanitachopra.com *.vanitachopra.com
ve9bx5qn.top *.ve9bx5qn.top
vegas108life.org *.vegas108life.org
viajesperfectosenmarruecos.com *.viajesperfectosenmarruecos.com
vibetking.xyz *.vibetking.xyz
vibetplay.xyz *.vibetplay.xyz
vibetsport.live *.vibetsport.live
vibrantzelira.com *.vibrantzelira.com
vip69.asia *.vip69.asia
vipaas112.com *.vipaas112.com
vipaas117.com *.vipaas117.com
virtue.finance *.virtue.finance
viveinternet.es *.viveinternet.es
vividtraveltrails.live *.vividtraveltrails.live
voyaretirrmentplans.com *.voyaretirrmentplans.com
vucomm.com *.vucomm.com
vulcan-platinumsloty.com *.vulcan-platinumsloty.com
vulcanrussia-vipclub.com *.vulcanrussia-vipclub.com
warwickmedia.com *.warwickmedia.com