Open
Cached
·
just now
96/100
SECURITY SCORE
Certificate Information
Subject
CN=ilost.co
Issuer
C=US, O=Amazon, CN=Amazon RSA 2048 M03
Valid From
May 27, 2025
Valid Until
June 25, 2026
204 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5F:A4:B3:4F:16:D9:02:2B:42:E3:2D:E6:E1:5E:E0:BC:89:27:46:BB:A5:7A:6C:3F:D4:DF:19:17:EE:AF:B4:34
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
Forward Secrecy
Limited
(Check cipher configuration)
Warnings
- • TLS 1.3 is not supported (recommended)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains;
Content-Security-Policy
Strong
default-src; script-src; style-src; +13 more
default-src 'self'; script-src 'self' 'nonce-EAkx1L7imH+30xbUMlphFA==' https://*.facebook.com https://connect.facebook.net https://*.fbcdn.net https://*.linkedin.com https://snap.licdn.com https://*.hotjar.com https://*.hotjar.io https://webforms.pipedrive.com https://leadbooster-chat.pipedrive.com https://*.pipedriveassets.com https://*.adyen.com https://cdn.crowdin.com https://*.google.com https://maps.googleapis.com https://*.gstatic.com https://www.recaptcha.net https://*.ilost.co https://stats.ilost.co https://cdn.builder.io https://js-agent.newrelic.com https://bam.eu01.nr-data.net https://unpkg.com ; style-src 'self' 'nonce-EAkx1L7imH+30xbUMlphFA==' https://*.facebook.com https://*.linkedin.com https://*.hotjar.com https://*.adyen.com https://cdn.crowdin.com https://fonts.googleapis.com https://*.google.com https://*.gstatic.com https://www.recaptcha.net https://*.ilost.co https://webforms.pipedrive.com https://*.adyen.com; img-src 'self' data: blob: https://*.adyen.com https://ct.capterra.com https://*.facebook.com https://connect.facebook.net https://*.fbcdn.net https://*.linkedin.com https://*.hotjar.com https://*.hotjar.io https://*.google.com https://maps.googleapis.com https://maps.gstatic.com https://*.gstatic.com https://www.recaptcha.net https://*.ilost.co https://cdn.builder.io https://cdn.builder.codes https://i.ytimg.com https://bam.eu01.nr-data.net https://www.paypalobjects.com https://ilost-customization.s3.eu-west-1.amazonaws.com/ ; font-src 'self' data: https://*.facebook.com https://*.linkedin.com https://*.hotjar.com https://fonts.googleapis.com https://*.gstatic.com https://leadbooster-chat.pipedrive.com; connect-src 'self' https://*.facebook.com https://connect.facebook.net https://*.linkedin.com https://*.hotjar.com https://*.hotjar.io https://*.googleapis.com https://*.google.com https://*.gstatic.com https://*.ilost.co https://stats.ilost.co https://leadbooster-chat.pipedrive.com https://cdn.builder.io https://bam.eu01.nr-data.net https://*.paypal.com https://*.adyen.com; frame-src 'self' https://*.ilost.co https://*.facebook.com https://connect.facebook.net https://*.linkedin.com https://*.hotjar.com https://crowdin.com https://*.google.com https://*.gstatic.com https://www.youtube.com https://www.youtube-nocookie.com https://www.recaptcha.net https://webforms.pipedrive.com https://cdn.builder.io https://*.paypal.com https://*.adyen.com; media-src 'self' https://*.ilost.co https://ilost-files.s3.amazonaws.com; object-src 'none'; base-uri 'self'; form-action 'self' https://ilost.co/* https://match.ilost.co/*; frame-ancestors 'self'; block-all-mixed-content; upgrade-insecure-requests; report-uri https://csp-api.ilost.co/cspdata-lambda;report-to csp-endpoint
X-Frame-Options
Good
sameorigin
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), autoplay=(), camera=(self), clipboard-read=(), clipboard-write=(), compute-pressure=*, display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), usb=(), xr-spatial-tracking=(), payment=(self), sync-xhr=(self)
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Wildcard CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 4 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts