Open
Cached
·
just now
85/100
SECURITY SCORE
Certificate Information
Subject
CN=www.verimail.io
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 27, 2025
Valid Until
February 25, 2026
89 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DD:2D:53:7A:C1:D9:1A:13:98:3A:22:12:05:EC:7E:46:4A:12:25:78:7A:CF:E9:17:EA:6C:7A:DF:A3:D7:9D:1E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Good
default-src; script-src; style-src; +10 more
default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://polyfill-fastly.io https://maps.googleapis.com https://apis.google.com https://unpkg.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'report-sample' 'self' https://translate.googleapis.com https://maps.googleapis.com https://app.launchdarkly.com https://clientstream.launchdarkly.com https://events.launchdarkly.com https://logs.browser-intake-datadoghq.com https://rum.browser-intake-datadoghq.com https://member-server.prod.eleanorhealth.io https://rs.prod.eleanorhealth.io https://unpkg.com; font-src 'self' https://fonts.gstatic.com https://unpkg.com; frame-src 'self' https://www.google.com; img-src 'self' data: blob: https://mysanctuary-images.imgix.net https://sanctuary-health-v4-images.imgix.net https://storage.googleapis.com https://maps.gstatic.com https://fonts.gstatic.com https://translate.google.com https://maps.googleapis.com https://www.eleanorhealth.com; manifest-src 'self'; media-src 'self' https://res.cloudinary.com https://storage.googleapis.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub449dae6ae721a93e38da72eeae1d807a&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Amember-client%2Cversion%3A437bbfe177d0d2011493a6104ff8ea3cc75938e8%2Cenv%3Aprod; worker-src 'self' blob:;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
eleanor.health
a2w.pro
adaept.com
www.agrobarnsley.com
link.alifbee.com
altamarcm.com
preview.ameroexteriors.com
quotes.amnova.co.za
www.andamp.com
artisanprinting.co
dev.athomearticulation.com
www.atlantissoftware.dev
www.atommuell-atlas.de
autoroot.ca
www.avogato.co
baileyhulsey.com
investors.bioceresgroup.com
bmepcgroups.com
bramtrabaho.com
v5.broxel.com
length-converter.at.calculatorhub.app
listener.cappisco.be
chillerfreezerrepair.com
tv.coibong30.app
collegesportsadvocate.com
iesco.com.ec
signode-demo.commerceq.com
www.convenientcode.dev
rastrear-guias-test.coordinadora.com
barbers-staging.cosmicoda.com
cuis.app
cvchamp.com
define.ag
depaulathleticscamps.com
easycurb.app
dev-links.ecredits.com
estudioenjambre.com
www.evok.dev
staging.onyx.fastsigns.com
dashboard.fcknew.com
fit-morning.pl
www.flightlinevr.com
app.floment.ai
egencia-staging-ideacloud.forgedx.com
jda-staging-ideacloud.forgedx.com
www.francisgallardo.com
frontendnorth.com
getvoxie.com
app-staging.giftable.com
gpprincipe.com
hfhsociety.com
firebase.st-sc-yard-management.gcp.homedepot.com
hudsonrha.com
www.hudsonrha.com
insightcheck.app
internet-of-unthings.com
www.jgsolutions.ca
vmi.katoomi.com
labs.keycloak.academy
knowtion.ca
lianncreative.com
linemed.it
www.liorrozin.co
lipperhub.com
lukasneo.com
maby.app
mai-score.com
makemywindoor.com
mediaprime.it
subt.mxdchn.com
www.nel-tec.org
food-app.neuon.ai
novaio.academy
oneminutecase.com
astro.orbyd.app
www.parlefrancais.org
kelseyanddan.pasmans.ca
www.pixelwavemedia.io
hx4a.projectboek.nl
queued.no
ravihomeloans.com
reachsummit.app
remotemonster.com
schiewe.dev
www.service-tech-hub.com
www.snode-ai.com
app.dev.strollhere.com
giftcirkul.technomata.com
teklinked.com
www.tharushawijayabahu.dev
thehoods.app
tomas-lesniak.de
luchaemenu.triggersplus.com
www.verimail.io
wekeep.app
go.wing.co
www.wnotes.app
tenant.woonig.app
writerlabs.me
www.yume-app.com
Other domains in certificate