80/100 SECURITY SCORE

Certificate Information

Subject
CN=crl.dwmas.ca
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 28, 2025
Valid Until
January 26, 2026 61 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AB:09:6D:A6:57:DC:1A:82:D1:B2:E2:53:15:D5:6D:D9:28:24:37:CF:AB:FF:87:F2:D7:31:E3:4D:AF:70:C2:8C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Configured (Restricts certificate issuance)
Current Issuer
Authorized (Matches CAA policy)
Recommendations
  • Consider using critical flag (flags=128) for stricter CAA enforcement
  • You have authorized 6 CAs - consider limiting to only the CAs you actively use
  • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts

Subject Alternative Names

100 domains
goodness-mercy.online

Other domains in certificate

11521491.peerly.app
auth.3dmodelunity.com
contact.advanda.app
admin.aitickets.cl
srws.almeraim.com
arihantinfo.net
www.arundanielk.dev
smokegrill.asap2go.com
editor.balintcsala.com
www.benandcory.com
bioflightvr.com
docs.blotch.app
dev.bluechew.com
ccl.boothpilot.com
calming.games
canabrava.site
www.certificadosisi.cl
cinqtortues.ca
mofa.dkh.co.in
www.cool-story-project.com
d2csquared.com
www.dating-tools.com
convert.denzildoyle.me
digitalsynapsis.com.br
next.dipanjanpanja.in
mentalhealthhub.dpd.co.uk
crl.dwmas.ca
app.euvokere.com.br
exploringsmartmusic.net
eyedoc.me
fastkoin.com
festive-functions.com
www.findyourstaytion.com
www.flemmetime.com
www.flextogether.com.au
www.agent.flux.chat
fomo-tv.com
formulair.app
frederickdeny.com
gamebit.company
www.geoproinc.com
web.grabbbitapp.com
hannahvine.com
s.hongkongcard.com
integertiles.com
interbellum.com
geotab.invyzn.io
justthecob.com
gastromasa-portal.kerzz.cloud
kydoscope.in
lepetit.app
letsfundit.app
www.martian.org
www.meals.tips
admin.medicalwisdom.in
megaprocalc.com
preflight.editor.objects.mergeedu.com
www.minersdiscount.com
mitratafood.com
payroll.mondayclub.io
morganann.io
moto-unity-adventures.com
mtcusa.co
musone.club
www.negravel.com
admin.noubodiez.com
www.noxive.com
dev-help.omnicurenow.com
twentyfourshopping.originsme.com
www.peachbeach.net
test-bed.peoplelens.ai
www.book.pharmachoice.com
www.philiplapinski.com
plusflow.me
preppa.io
www.procaryote.com
quentindesbois.me
spark.read.land
www.reinhardschnetzinger.com
www.revrecai.com
www.sahl.menu
democumbre.sapiolab.co
saywhataga.in
www.sevendaysoffire.com
snepsts.xyz
stackhire.site
www.supermercados46.com.br
www.tandemanalytics.com
indiealliance.tf6.dev
thephobosplan.com
www.tortilleriachapa.com
trustdigisign.com
www.vlogmanager.com
partner.wexer.com
whatthefuckismyelectrificationstrategy.com
www.whiteharttearoom.co.uk
vendor.whyleavetown.com
yachtrobotics.com
www.yafts.app