76/100 SECURITY SCORE

Certificate Information

Subject
CN=mwstudio.site
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 09, 2026
Valid Until
April 09, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
85:14:0E:11:8C:25:10:79:9E:B7:37:45:0B:56:F9:70:6E:B2:5B:96:ED:2D:6E:FF:8E:4B:BE:50:E6:7E:A6:E2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
coastauction.com *.coastauction.com *.blog.coastauction.com *.bonus.coastauction.com *.cit.coastauction.com *.einstein.coastauction.com *.intern.coastauction.com *.ntp.coastauction.com *.olga.coastauction.com *.pool.coastauction.com *.pop.coastauction.com *.pop2.coastauction.com *.publicapi.coastauction.com *.resources.coastauction.com *.search.coastauction.com *.slave.coastauction.com *.team.coastauction.com *.test3.coastauction.com *.ww38.coastauction.com

Other domains in certificate

airwest.fun *.airwest.fun *.www.airwest.fun
*.access.donahues.com *.asp.donahues.com *.catalog.donahues.com *.connect.donahues.com donahues.com *.donahues.com *.login.donahues.com *.mail.donahues.com *.mail10.donahues.com *.mailhost.donahues.com *.mx01.donahues.com *.mx4.donahues.com *.newmail.donahues.com *.old.donahues.com *.posta.donahues.com *.remote.donahues.com *.sitemap.donahues.com *.sitemaps.donahues.com *.smtps.donahues.com *.store.donahues.com *.vpn.donahues.com *.wahsbsslvpn.donahues.com *.webaccess.donahues.com *.wildcard.donahues.com *.ww.donahues.com *.ww25.donahues.com *.ww38.donahues.com
kocherequestrian.com *.kocherequestrian.com *.ww25.kocherequestrian.com
mwstudio.site *.mwstudio.site *.www.mwstudio.site
sandigadigital.com *.sandigadigital.com *.webmail.sandigadigital.com
*.activate.spetrum.net *.activide.spetrum.net *.mobile.spetrum.net *.pi.spetrum.net *.spectra-sit.spetrum.net spetrum.net *.spetrum.net *.watch.spetrum.net *.webmail.spetrum.net *.ww1.spetrum.net *.ww16.spetrum.net *.ww25.spetrum.net *.ww38.spetrum.net
*.autodiscover.thebrownpaperbag.net *.cpanel.thebrownpaperbag.net *.cpcalendars.thebrownpaperbag.net *.cpcontacts.thebrownpaperbag.net *.dk.thebrownpaperbag.net *.no.thebrownpaperbag.net *.se.thebrownpaperbag.net *.staging1.thebrownpaperbag.net *.staging4.thebrownpaperbag.net thebrownpaperbag.net *.thebrownpaperbag.net *.webdisk.thebrownpaperbag.net *.webmail.thebrownpaperbag.net
*.parked.traveleze.co.uk traveleze.co.uk *.traveleze.co.uk
*.out.trekgleam.xyz trekgleam.xyz *.trekgleam.xyz