77/100 SECURITY SCORE

Certificate Information

Subject
CN=f.thursday.link
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 14, 2025
Valid Until
January 12, 2026 52 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0C:DB:30:D6:07:4E:35:41:17:C0:B0:29:EC:97:D4:F7:4D:8A:F0:C7:63:AC:4D:63:3A:AC:7C:CB:B8:55:8E:98
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
inquery.hulic-agency.com

Other domains in certificate

1droptaxi.com
www.abeceda.app
abnormalangles.com
englishtraining.bsru.ac.th
welcome.acaciamoney.com
www.academix.dev
configurator.airkoning.nl
www.amooto.it
arcticreply.com
avishayb.me
ayurdiayurveda.com
www.ballroom.app
link.bkr.com.ar
bracescoinversiones.com
www.cardinalstepinac.com
careyo.life
share.cf.me
charlesmoll.fr
uat-gcp-admin.tops.co.th
databoosts.info
www.didakt.io
edorta.it
core.elinmejorable.com
epochtimestamp.com
www.family-locator.app
fertilab-bo.com
9ii.freshii.com
garybond.co.uk
gdtrack.com.mx
www.goldenhillpainting.com
beta.gridty.com
haqimhaslee.my
helpless.ai
app-sandbox.homebox.co.uk app-staging.homebox.co.uk
inclub.site
investwithdarwin.com
amortization.jhoor.com
jiye-lee.com
www.joshcunn.dev
jurdiconsult.media
knowledgeofweird.com
www.app.learningsuite.io
www.maheshwariskincare.com
mailattach.co
login.mehulkapadia.in
melodrill.com
www.metroplexcricket.club
js-damage-calc.millergeek.xyz
morenoise.it
mponengfencing.com
mrcy.app
mybegroting.co.za
www.crm-admin.myelinz.com
nakata.tech
on-the-planet.com
client.onefx.in
lecture.opatry.net
www.taofoundation.org.tw
ourekam.com
patents.outerspaceip.com
admin.pharm2market.app
extension.plugapp.jp
pocobase.com
point876solutions.com
discover.polymerize.io
primarycareofnevadallc.com
procliq.com
readaloudforme.com
orderonline.rochypizza.com.au
rodstickers.com
www.routezero.world
www.russellyazbeck.com
www.sanlazer.net
sdemonk.com
www.silvergray.in
sipsync.vip
citadellacorti.sky-boy.com
www.snoufai.com
www.socalledsidefx.com
www.softsignal.co
www.suivezcolis.com
t-hoffman.com
koro2.tailcode.io
novagelato.thediners.in
f.thursday.link
link.ulo.life
www.ureshii-desu.com
vanessabterapeuta.com
auth.verbuu.com
villaart.com.ar
vishwakarmaengineering.org
onedrive.vnetes.com
www.waivethewait.com
demo.staging.wallit.app
whiteorangestudio.com
ws.workspace.training
yaky.online
app.yo-yo.ai