SSL Verification Bypassed

The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.

Reason:

Expired Certificate - the server's certificate has expired

62/100 SECURITY SCORE

Certificate Information

Subject
CN=darkvch.store
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 19, 2025
Valid Until
December 18, 2025 Expired
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C3:CB:BC:10:89:E6:B2:16:A2:48:BF:66:30:BA:DF:F5:F9:E3:6D:2D:E1:D2:C6:56:45:F4:90:60:DC:35:94:93
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
forms.cemtrik.com

Other domains in certificate

www.2zgroupsolutions.com
www.32shot.com
9yardlogistics.com
dev-sagt-admin.acuizen.com dev-sagt.acuizen.com
agridigi.com
armolaw.com
asso-mascareignes1789.com
www.atlantisgymcr.com
www.atlyapim.com
www.automaksud.ee
static.shopify.axinan.com
balanceoffice.com
yaqoutetmarjane-hadith.bethictech.com
boollpalpites.com.br
bucketeer.io
centerofmonitoring.xyz
fibersoft.com.tr
darkvch.store
dhverse.com
diagauto.ai
www.dsmachining.co.uk
dubaipipes.com
www.eladyosef.com
acentos.eldiario.es
christmas-countdown.fedmich.com
auth.fluenday.com
futurehube.com
geonit.ca
getblackout.app
glowbydlo.be
goldfield.space
www.gonzaloarenasf.cl
app.guvi.in
quid.haikuthunder.com
staff.hurreytech.com super.hurreytech.com
hypesociety.shop
bssd.impactwrap.com
tecnovale.ind.br
dev-app.indoc.co.za
jddios.com
www.jillianashleybruyere.com
www.johncolumbo.com
www.kashima.dev
suite.kmcnellis.com
knowvee.com
hooks.kood.dev
krnic.be
www.kunalganglani.com
contracts.leanabogados.com
linahakobyan.com
linktrip.co.jp
lojaxalingobrinquedos.com.br
lumenmedic.com
mcgeary.dev
conf.meetnow.in
memproxi.com
www.mitchellcemetery.org
hylo.dev.mk.mw
ngakela.com
niunauto.com
my.nor.by
onepuppyaday.com
cpland.originsme.com
auth.ozengine.jp
www.parkmybike.dev
sri-lanka.pittborndigital.com
roadandrail.portal.plenadata.com
about.pointplusksa.com
elevadorhidraulico.polipastosqueretaro.mx
storage.profitableservices.com
mori.propelfuels.net
solar.pukky-it.com
puyos.im
www.quickexams.co.za
fulfyld.rabot.us
ncr.raxar.com.ar
dev.sharo.io
shroom.id
skillsbankme.com
app.smilecat.com
sofiacamprubi.ch
www.sonnyaguilar.com
sreedatthacncinterio.com
stacktechnologygroup.com
syntagi.in
www.tantei.lol
teachingboost.fr
thebrokegrad.com
thenxtacademy.com
ticketand.co.jp
toetan.com
www.topotech.org
traditionequipmentleasing.com
clientsignup.truecordis.co initialsignup.truecordis.co
ysmithnd.com
wax-testnet.zeptagram.com