76/100 SECURITY SCORE

Certificate Information

Subject
CN=snellefietser.be
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 31, 2025
Valid Until
March 31, 2026 49 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
05:01:B3:B3:79:70:84:F4:DB:3B:D3:07:DF:D5:12:A9:BC:4D:DA:4E:EB:AA:F2:E7:16:94:11:8A:8B:18:77:57
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

75 domains
spcollege.com *.spcollege.com *.edupluscampus.spcollege.com *.gmail.spcollege.com *.live.spcollege.com *.myspcmail.spcollege.com *.wildcard.spcollege.com *.ww16.spcollege.com *.wwww.spcollege.com

Other domains in certificate

aquitainagri.org *.aquitainagri.org
australianinvesting.com.au *.australianinvesting.com.au *.wildcard.australianinvesting.com.au
babyboo.store *.babyboo.store
banteng77coy.click *.banteng77coy.click
braesinterfaithministries.com *.braesinterfaithministries.com
chioptle.com *.chioptle.com *.ildcard.chioptle.com
*.asp.cityfreshfoods.com cityfreshfoods.com *.cityfreshfoods.com *.digital.cityfreshfoods.com *.esg.cityfreshfoods.com *.oobesaas.cityfreshfoods.com *.trabajo.cityfreshfoods.com *.w.cityfreshfoods.com
electionpolls.com.au *.electionpolls.com.au
*.ci-preprod.esmacer.com esmacer.com *.esmacer.com *.hostmaster.esmacer.com *.mail.esmacer.com
izecc.io *.izecc.io
*.com.mariahwe.com mariahwe.com *.mariahwe.com
*.app.metaall.club metaall.club *.metaall.club
*.bbs.onedrvie.com onedrvie.com *.onedrvie.com
outsourcingforcros.com *.outsourcingforcros.com
picwiser.com *.picwiser.com *.random.picwiser.com *.ww16.picwiser.com *.ww25.picwiser.com
*.new.revancerextended.io revancerextended.io *.revancerextended.io
seniorcruise-esop.site *.seniorcruise-esop.site
skimr.co *.skimr.co
snellefietser.be *.snellefietser.be
thaoduoctamdaovn.click *.thaoduoctamdaovn.click
uweprowrestling.com *.uweprowrestling.com
whichgin.com *.whichgin.com
yashmarathon.com *.yashmarathon.com
ytdo7zq7.click *.ytdo7zq7.click