Open
Cached
·
just now
94/100
SECURITY SCORE
Certificate Information
Subject
CN=doorbell.io
Issuer
C=US, O=Let's Encrypt, CN=E8
Valid From
November 10, 2025
Valid Until
February 08, 2026
78 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
AC:58:4A:B2:F0:EF:F4:BA:92:19:BF:E5:DD:E6:FF:3F:A4:D6:82:1B:D9:95:AE:D9:F8:24:07:37:4A:C1:A8:03
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains
Content-Security-Policy
Good
default-src; connect-src; img-src; +6 more
default-src 'self'; connect-src 'self' wss://doorbell.io https://embed.doorbell.io https://use.typekit.net https://sentry.io https://performance.typekit.net https://api.stripe.com https://api.mixpanel.com https://api-js.mixpanel.com https://o5857.ingest.us.sentry.io https://cdn-eu.usefathom.com; img-src * data:; font-src 'self' data: https://use.typekit.net https://use.fontawesome.com https://fonts.bunny.net; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://embed.doorbell.io https://use.fontawesome.com https://fonts.bunny.net; script-src 'self' 'unsafe-inline' data: https://dl.frontapp.com https://cdnjs.cloudflare.com https://js.sentry-cdn.com https://browser.sentry-cdn.com https://embed.doorbell.io https://js.stripe.com https://use.typekit.net https://cdn.mxpnl.com https://www.google.com https://www.gstatic.com https://code.jquery.com https://cdn.headwayapp.co https://unpkg.com https://cdn-eu.usefathom.com https://js.pusher.com https://cdn.jsdelivr.net; frame-src 'self' https://js.stripe.com https://www.google.com https://headway-widget.net; frame-ancestors 'self' https://app.frontapp.com; report-uri https://o5857.ingest.us.sentry.io/api/11166/security/?sentry_key=e7921f9f0ac34892b05e93a72853ad9e&sentry_environment=production
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Incident Reporting
mailto:[email protected]
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'issuewild' records to control wildcard certificate issuance