Open
Cached
·
just now
94/100
SECURITY SCORE
Certificate Information
Subject
CN=go-vip.co
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
January 13, 2026
Valid Until
April 13, 2026
75 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
6A:5B:C6:0D:CF:1F:17:41:16:A2:B9:57:01:34:55:14:C5:35:7E:66:C6:76:8C:42:AB:A5:A3:EE:E9:C7:18:54
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000
Content-Security-Policy
Basic
default-src; script-src; img-src; +4 more
default-src 'unsafe-eval' 'unsafe-inline' * blob:; script-src 'unsafe-inline' 'unsafe-eval' * blob:; img-src * data:; connect-src *; font-src * data:; upgrade-insecure-requests; block-all-mixed-content
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Present
microphone=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
letsencrypt.org
; validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/36334489
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
- • Consider adding 'issuewild' records to control wildcard certificate issuance