Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.3sy.it
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 25, 2025
Valid Until
January 23, 2026
58 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4B:20:52:B1:7C:39:71:AA:FD:00:4D:9F:70:5F:D2:15:C4:49:01:F0:E2:D5:05:DD:36:7D:8B:34:58:6D:1C:0B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
jayscancerjourney.com
www.3sy.it
exam.academeplus.com
www.aclaralab.com
aintwrong.com
fixthebudget.americaoffbalance.com
amsuarez.com
sar6.apoio.tech
dynamic-links.bngolf.jp
www.bonburger.mx
byggis.no
app.canalmaissaude.com.br
www.carjoky.com
cenaka-intern.com
www.centragreens.com
chicagoteluguassociation.org
china-chats.net
cloudroom.io
squareimages.co.in
shrijaldahal.com.np
www.davidgalindo.dev
io.dev.deeploop.com
dustingonzales.com
www.esbprogram.ca
festopya.com
admin.flairboat.com
www.friendsandfamilymarket.com
goagro.eu
dev.goocean.io
www.goulao.pt
happyrobots.pro
community.staging.icares.app
dm-q.dev.interviewui.com
app.invoicenow.asia
ssa.onsite.invue-live.com
www.jacksonrobert.com
jagrutiimacs.com
blog.jexport.ci
admin.keatsclothing.com
client.keatsclothing.com
fh.kvint.me
leclercqantiquites.com
booking.legacyfarmproject.ca
omnicronlab.lernit.app
dapay.linkeddots.com
liquidcodeify.in
dashboard.louisvillelowvoltage.com
stats.m-link.no
www.matterhorn-immobilien.ch
mijnmarkt.nu
mlynaric.cz
nao.md
bubbleforce.newmagicalworld.com
newmizrachy.oz-tms.com
profileanalyser.pansolutions.com.br
www.philomena-art.com
phoenix-artworks.be
vodafonespain.platformkids.com
www.poodoku.app
porkshop.ca
dev3.dk.cpc.porsevej.dk
rahulkumartech.in
orders.revoolt.me
gdp.rflex.dev
salehhammudeh.com
www.seanfinnan.com
secrethandshake.dev
sellularity.org
es.app.sently.io
www.slips.im
stg.snappers.tv
sprinterbus51.ru
spruch.ru
online.sqcf.org
www.stb-pott-meyer.de
undersokelse.synergy.no
www.tailoredresources.com.br
coordinador.taxib.mx
fall.telehearportal.com
www.the-studio91.com
thebudgie.com
tkb.cards
trashtracker.app
troysimon.com
pwa-masoncounty.trueomni.com
tseller.com.br
www.twizzr.com
txtarea.com
use-third.com
www.uskidsgolfscoreboard.com
www.valenciastock.com
valorimovel.com.br
viktor-stefanov.dev
viluk.com
recording.voicekeepsakes.com.au
wappgpt.com
yazool.se
youtopi.us
ytec.ca
zenysapp.com
Other domains in certificate