Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.spaceenergiaeletrica.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 12, 2026
Valid Until
April 12, 2026
81 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1C:B1:C9:4B:C1:1A:4E:AA:3C:E8:29:B5:6C:06:CC:8F:D8:FE:C6:AC:AD:45:4F:DA:1F:29:71:E9:E9:85:FC:A3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
failstate.in
acadioncloud.com
anankex.com
pos.apps2serve.com
www.aserstein.fr
planner.aurastudios.nl
autoport40.es
dev.avicado.net
axentia.shop
www.beadapp.io
bigideas.guru
link.busikua.com
byabdalrahman.com
caravan-ved.ru
carbonclear.io
cmnconnect.org
theconnexions.co.in
www.perfectcapture.co.in
spout.co.zm
colegiomontana.com
www.kbg.com.kw
compensadosnn.com.br
trouver-une-place.creche-and-go.fr
daascene.com
pwa-poc.daobui.nl
dobbrick.info
easyfarming.org
dev.app.eatit.kr
www.kasra.edalat.dev
emilstabs.org
ettonnye.com
www.ettonnye.com
cal.ffhq.de
swishy.fi8.xyz
fragile-handlewithcare.com
timesheet.genesis-consult.com
staging.genevaprotection.com
geniefy.de
gewerbenebekostencheck.com
www.gewerbenebekostencheck.com
gvstrmrgh.co.za
admin.harmonised.co.nz
homestrings.com
sideps.idepsms.org
www.infer-know.com
ag-de-dev.input4you.be
www.jedbrennen.me
jingliuhua.cfd
www.jingliuhua.cfd
mealmate.jklm.co.za
jksatyacareers.org
jobs-pedia.com
app.jolisms.com
www.julkisivupojat.fi
kashifkhan.org
key2key.digital
www.key2key.digital
lanhuaxi.cfd
www.lanhuaxi.cfd
losslessenergy.com
www.maneaionut.ro
www.mayaedu.org
www.dashboard.meupet.io
momendstats.com
www.motorcampeao.com.br
mushwork.com
nadersproductions.com
nebenkostenabrechnung-check.com
www.nebenkostenabrechnung-check.com
newmnemosyne.com
assets.parcelquest.co.za
pascal-projects.me
please-box.com
primeinfosolution.com
www.psiholog-dariana-barbulescu.ro
sabkuuch.online
master.saius.es
www.seven7meals.it
simonmarini.top
smfresidencial.com
solarcon.store
www.spaceenergiaeletrica.com.br
inbox-staging.staffshift.com
supereffective.tips
matl.tech-college.jp
www.technikilinowe.pl
thelobby.studio
www.tiespro.co.za
tigieducation.com
tradestosheets.com
business2.tuttocarrellielevatori.it
upstreams.net
vectrastrategy.com
admindashboard2staging.viralfission.com
wipa.no
wochi.vn
consent.your.vet
www.zhouya.cfd
zhouya.cfd
educator.dev.zlipp.in
Other domains in certificate