77/100 SECURITY SCORE

Certificate Information

Subject
CN=pozzimaquinas.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 08, 2025
Valid Until
January 06, 2026 52 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A8:6D:BB:13:6F:37:8F:65:DB:32:97:B8:6D:A2:44:93:80:AF:2C:DD:AC:67:1C:E1:4F:2A:E8:7C:13:EC:54:6D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
fall-qa.telehearportal.com

Other domains in certificate

5dthinking.ca
www.adamanthony.co.uk
portfolio.afroup.com
www.alexjatopi.fi
saac03.antoniogalanti.com
australianmarinediscounters.com.au www.australianmarinediscounters.com.au
studio.backlight.dev
bassoimoveisrs.com.br
www.binarybotz.com
www.brainkos.com
calinlucian.com
www.chargehanger.com
www.nitro.co.th
codetrackerai.com
www.codyflood.com
app.complia.io
packages.conditions.digital
convosys.in
coolneighbors.com
beattap-notice.cosgy.dev
kilo.dev-kanaeokana.net
dharoma.in
diego-bruno.dev www.diego-bruno.dev
gxdoc.digitalprojex.dev
www.digitalsynapsis.com.br
drops.finance
www.duelist.me
dypran.com
ecoev.io
epicroutes.fun
app.fansonchain.ai
fortunehomecare.com
freeheictojpgs.com
www.fundile.com
gdwrk.link
cx.gqsecure.com
www.mijn.heenenweervervoer.nl
www.hhfm.me
agnl-de-testing02.input4you.be
mini-warehousing.ipigeon.institute
itjob.by
jblewandowski.com
share.joinly.live
kang.in
admin.koma-tour.fun
kwikmedia.in
tools.lalita.vn
notes.lemus.io
lesrelaiscartegrise.fr
www.mahoro.jp
www.majdielfelah.co.uk
www.docs.maraikka.com
www.martinslopes.com.br
www.mega-dj.de
game.mick4k.com.br
listr.mobileappster.co.uk
www.motemahub.tech
booli.demo.movello.se sbc.demo.movello.se
www.neurekalab.com
video.novo.health
www.nxgenpro.com
ongevalrisico.nl
api.mobile.onshop.lk
dashboard.xpay.optimasysdev.com
hashtag.parthvirani.com
www.ph2.io
pozzimaquinas.com.br
pulcer.net
troisfoisplushaussmann.order.pulp.eu
www.qnailsspa-sandysprings.com
quizletz.com
rankrushdigital.com
runningstats.app
sandbox.demo.members.sargon.com
get.singtosay.com
app.sitwithme.live
invest.skwai.com
spotifypartyti.me
adminsite.sriharinicrackers.com
staco-system.com
stardust-distro.org
stage.client.stylers.cloud
service.sysmog.com
tourmate.tammeir.com
www.therightquestion.dev
www.tinyview.com
trustmile.co
www.typo3-association.org
umairshaque.com
smashup.victorjouin.com
app.voicequestionnaire.com
wiltshire-global.com
yagole.jp
yallaclash.com
yankov.se
post.zzoman.com