Open
Cached
·
just now
90/100
SECURITY SCORE
Certificate Information
Subject
CN=*.gfn.de
Issuer
C=PL, O=Asseco Data Systems S.A., CN=Certum DV TLS G2 R39 CA
Valid From
October 23, 2025
Valid Until
October 23, 2026
299 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F6:2F:13:15:A8:89:A5:9D:95:01:DE:67:AE:2A:9E:03:4E:65:25:F1:DD:1D:FE:06:06:1B:BB:0B:A0:A0:0B:C4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=63072000; includeSubDomains
Content-Security-Policy
Basic
default-src; base-uri; connect-src; +8 more
default-src 'self' secure.gravatar.com www.etermin.net develop.gfn.de staging.gfn.de www.gfn.de chatbot.gfn.de jnn-pa.googleapis.com maps.googleapis.com fonts.gstatic.com maps.gstatic.com www.gstatic.com rns.matelso.de www.google.com googleads.g.doubleclick.net i.ytimg.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com yt3.ggpht.com cdn.join.com join.com yoast.com ps.w.org s.w.org ninjaforms.com cdn-public.borlabs.io ams.wpml.org ate.wpml.org; base-uri 'self'; connect-src 'self' seo.gfn.de seo3.gfn.de api.ipify.org region1.google-analytics.com region1.analytics.google.com play.google.com www.google.com www.googletagmanager.com o2.mouseflow.com eu01.rec.mouseflow.com www.youtube-nocookie.com www.facebook.com rns.matelso.de www.etermin.net stats.g.doubleclick.net jnn-pa.googleapis.com maps.googleapis.com bat.bing.com bat.bing.net yoast.com ams.wpml.org ate.wpml.org psb.taboola.com trc-events.taboola.com trc.taboola.com pips.taboola.com cds.taboola.com cdn.join.com join.com px.ads.linkedin.com api.digiaccess.org newassets.hcaptcha.com j2xdcu.gfn.de; font-src 'self' data: fonts.gstatic.com cdn.join.com cdn.mouseflow.com; frame-ancestors 'self' develop.gfn.de staging.gfn.de www.gfn.de chatbot.gfn.de www.etermin.net join.com; frame-src 'self' blob: develop.gfn.de staging.gfn.de www.gfn.de chatbot.gfn.de www.etermin.net join.com jnn-pa.googleapis.com maps.googleapis.com play.google.com www.google.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com api.wppopupmaker.com testbot-gfn.assono.de td.doubleclick.net; img-src 'self' data: develop.gfn.de staging.gfn.de www.gfn.de play.google.com www.google.com www.google.de ajax.googleapis.com googleads.g.doubleclick.net www.googletagmanager.com trc.taboola.com maps.gstatic.com jnn-pa.googleapis.com maps.googleapis.com fonts.gstatic.com bat.bing.com bat.bing.net yt3.ggpht.com i.ytimg.com rmsi-4008-adswizz.attribution.adswizz.com chatbot.gfn.de testbot-gfn.assono.de secure.gravatar.com 0.gravatar.com s.wordpress.com ps.w.org s.w.org ts.w.org cdn-public.borlabs.io www.kadencewp.com ninjaforms.com i.imgur.com updates.arscode.pro tp-cdn.wpml.org wpml.org toolset.com criticalcss.com sp-ao.shortpixel.ai d1lsub6zbh43gv.cloudfront.net optimizingmatters.com www.facebook.com cdn.join.com www.youtube-nocookie.com patterns.startertemplatecloud.com toucan.kadencewp.com px.ads.linkedin.com px4.ads.linkedin.com download.digiaccess.org j2xdcu.gfn.de; media-src 'self' www.youtube-nocookie.com www.youtube.com cdn-public.borlabs.io; object-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' ajax.googleapis.com jnn-pa.googleapis.com maps.googleapis.com play.google.com www.google.com www.gstatic.com googleads.g.doubleclick.net www.google-analytics.com rns.matelso.de chatbot.gfn.de testbot-gfn.assono.de develop.gfn.de staging.gfn.de www.gfn.de j2xdcu.gfn.de www.googletagmanager.com cdn.mouseflow.com connect.facebook.net bat.bing.com bat.bing.net cdn.taboola.com trc.taboola.com www.youtube.com www.youtube-nocookie.com www.etermin.net join.com ams.wpml.org ate.wpml.org widget.join.com snap.licdn.com px.ads.linkedin.com download.digiaccess.org api.digiaccess.org challenges.cloudflare.com js.hcaptcha.com; style-src 'self' 'unsafe-inline' chatbot.gfn.de testbot-gfn.assono.de www.youtube-nocookie.com jnn-pa.googleapis.com maps.googleapis.com fonts.googleapis.com ajax.googleapis.com play.google.com www.google.com www.googletagmanager.com ams.wpml.org ate.wpml.org cdn.join.com patterns.startertemplatecloud.com download.digiaccess.org api.digiaccess.org j2xdcu.gfn.de;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Present
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports