76/100 SECURITY SCORE

Certificate Information

Subject
CN=trgit.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 19, 2026
Valid Until
June 17, 2026 41 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F4:CF:FF:41:30:50:E6:D0:7D:26:12:80:18:29:9E:23:60:9C:CC:33:69:9A:D7:C6:3E:F3:1F:2F:11:51:2E:0E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
mxsa.com *.mxsa.com *.alwaili.mxsa.com *.factorym.mxsa.com

Other domains in certificate

aftermeeting.com *.aftermeeting.com
amorrow.com *.amorrow.com *.vpn2.amorrow.com
asbestosguide.com.au *.asbestosguide.com.au *.ww17.asbestosguide.com.au *.ww25.asbestosguide.com.au *.www.asbestosguide.com.au
bloomizon.com *.bloomizon.com *.mg.bloomizon.com
bravodates.com *.bravodates.com *.ww25.bravodates.com
cigarsnmore.com *.cigarsnmore.com *.sitemap.cigarsnmore.com
disii.com *.disii.com
*.abc.elpedregal.com *.api.elpedregal.com *.backup.elpedregal.com *.ci.elpedregal.com *.control.elpedregal.com elpedregal.com *.elpedregal.com *.es.elpedregal.com *.ica-gestagro-v5-production-api-packing.elpedregal.com *.library.elpedregal.com *.packing.elpedregal.com *.uk.elpedregal.com
*.backend.freemasonwebsite.com *.demo.freemasonwebsite.com freemasonwebsite.com *.freemasonwebsite.com *.sitemaps.freemasonwebsite.com *.staging.freemasonwebsite.com
*.4euzgnlr4n8.kiw.com *.cmn2.kiw.com *.dbmubfm.kiw.com *.fwa.kiw.com *.fx.kiw.com *.gov.kiw.com *.gr3ncl.kiw.com kiw.com *.kiw.com *.lolo.kiw.com *.mc-weblink.kiw.com *.mta.kiw.com *.ptfha6m.kiw.com *.qla.kiw.com *.twincoastcycletrail.kiw.com *.u4z.kiw.com *.zerin.kiw.com
laborunions.us *.laborunions.us *.ww25.laborunions.us
mitchellsphysio.com *.mitchellsphysio.com
monkeyworks.com *.monkeyworks.com
npf.com.pl *.npf.com.pl
*.ildcard.pharmacyinformation.com pharmacyinformation.com *.pharmacyinformation.com
privatetrust.com.au *.privatetrust.com.au
*.ar.rizmo.online rizmo.online *.rizmo.online
rustdeck.com *.rustdeck.com *.ww17.rustdeck.com *.ww38.rustdeck.com
supplizio.net *.supplizio.net *.ww16.supplizio.net
technnokade.com *.technnokade.com *.ww25.technnokade.com
trgit.com *.trgit.com