Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=f.thursday.link
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 14, 2025
Valid Until
January 12, 2026
52 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0C:DB:30:D6:07:4E:35:41:17:C0:B0:29:EC:97:D4:F7:4D:8A:F0:C7:63:AC:4D:63:3A:AC:7C:CB:B8:55:8E:98
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
inquery.hulic-agency.com
1droptaxi.com
www.abeceda.app
abnormalangles.com
englishtraining.bsru.ac.th
welcome.acaciamoney.com
www.academix.dev
configurator.airkoning.nl
www.amooto.it
arcticreply.com
avishayb.me
ayurdiayurveda.com
www.ballroom.app
link.bkr.com.ar
bracescoinversiones.com
www.cardinalstepinac.com
careyo.life
share.cf.me
charlesmoll.fr
uat-gcp-admin.tops.co.th
databoosts.info
www.didakt.io
edorta.it
core.elinmejorable.com
epochtimestamp.com
www.family-locator.app
fertilab-bo.com
9ii.freshii.com
garybond.co.uk
gdtrack.com.mx
www.goldenhillpainting.com
beta.gridty.com
haqimhaslee.my
helpless.ai
app-sandbox.homebox.co.uk
app-staging.homebox.co.uk
inclub.site
investwithdarwin.com
amortization.jhoor.com
jiye-lee.com
www.joshcunn.dev
jurdiconsult.media
knowledgeofweird.com
www.app.learningsuite.io
www.maheshwariskincare.com
mailattach.co
login.mehulkapadia.in
melodrill.com
www.metroplexcricket.club
js-damage-calc.millergeek.xyz
morenoise.it
mponengfencing.com
mrcy.app
mybegroting.co.za
www.crm-admin.myelinz.com
nakata.tech
on-the-planet.com
client.onefx.in
lecture.opatry.net
www.taofoundation.org.tw
ourekam.com
patents.outerspaceip.com
admin.pharm2market.app
extension.plugapp.jp
pocobase.com
point876solutions.com
discover.polymerize.io
primarycareofnevadallc.com
procliq.com
readaloudforme.com
orderonline.rochypizza.com.au
rodstickers.com
www.routezero.world
www.russellyazbeck.com
www.sanlazer.net
sdemonk.com
www.silvergray.in
sipsync.vip
citadellacorti.sky-boy.com
www.snoufai.com
www.socalledsidefx.com
www.softsignal.co
www.suivezcolis.com
t-hoffman.com
koro2.tailcode.io
novagelato.thediners.in
f.thursday.link
link.ulo.life
www.ureshii-desu.com
vanessabterapeuta.com
auth.verbuu.com
villaart.com.ar
vishwakarmaengineering.org
onedrive.vnetes.com
www.waivethewait.com
demo.staging.wallit.app
whiteorangestudio.com
ws.workspace.training
yaky.online
app.yo-yo.ai
Other domains in certificate