Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=dev.retail-hawk.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 24, 2025
Valid Until
February 22, 2026
86 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
98:B8:B3:E7:10:E4:D6:28:26:FF:28:E9:D8:8E:09:0D:C3:C2:0F:BF:AB:53:E6:E8:D6:30:C5:C3:89:13:D0:D6
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
equippers-si.co.nz
wibernet.28east.co.za
hml.app.4show.live
bing.51tk.net
aimforchange.97percent.us
aarondetrick.com
a.alterodenwald.de
4foro.ampip.mx
benaton.net
boostmybuild.co.uk
bostonfood.app
app.cambri.ai
mundofino.clau.io
app.lunacrm.co.il
miembros.apart.com.pa
digisailor.com.sg
hakanozer.com.tr
cosmodity.tech
www.cosmodity.tech
darrenrobertlee.dev
www.dreijer-it.nl
duotai.app
eepcloud.no
www.eljordan.co
fantasyfootballstats.org
a0a2.foodle.su
www.get-blend.com
www.gilbertmania.page
www.googify.net
www.grampanchayatambora.in
greendroptaxi.in
ha.family
harryjacks.co.uk
hugop.dev
ikjunekim.net
creixerjunts.itera.es
itslearnable.co.za
www.jiin.love
www.jzims.app
www.kehinde.dev
lionparcel.kuburayaprinting.com
www.ladbon.net
app.learningwith.ai
stg.letterfan.jp
app.moonprint.in
www.myukbuilders.co.uk
myvtcmanager.fr
app.narratify.ai
nativefarmer.in
neocalc.sk
notnot.io
aleph.org.mx
www.hcfn.org.ng
outfitz.ai
www.peartech.in
streifenshirt.petit-bateau.de
www.picksixtyfour.com
speedtest.pixnet.io
app.poxp.xyz
printhubdesigns.in
www.pxl.live
www.qr4.xyz
www.reevia.fr
referro.xyz
admin.renaultplr.com.br
temueve.rentandes.com
dev.retail-hawk.com
rmembr.app
connect-ng-work-order.rxoconnectint.rxo.com
chumbawumba.ryandea.me
docs.scalegrowth.ai
corona.schmidt-allgaeu.de
www.scoupar.dev
nft.peresnoelverts.secourspopparis.org
shnap.org
sidekick.health
skiplaces.app
sneaksnake.com
somosadoracion.com
sozofestivals.com
www.startupfo.rest
www.stevendelitta.com
bodatorreslopez.swanmoments.lat
istore.swyft.com
firebase666.t9platform-ph.com
www.tektronconsulting.com
dev.the-curry.app
scoring-dashboard.theloomaproject.com
thesbpro.org
totallydifferent.co.nz
www.triprecordings.com
app-dev.upflowy.com
usedautopartssupplies.com
valentinafitmoda.com
victornazzaro.com
www.vkrds.com
wikmit.fr
winzup.org
yepmile.com
www.yourcall.in
Other domains in certificate