Open
Cached
·
just now
80/100
SECURITY SCORE
Certificate Information
Subject
CN=philbaylog.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 26, 2025
Valid Until
February 24, 2026
85 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3B:A8:74:C3:0A:5C:09:FF:8F:73:ED:03:74:56:1D:BF:3B:E3:8C:6E:86:35:83:8D:79:2C:26:E1:C4:CF:10:37
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Wildcard CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 6 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
Subject Alternative Names
100 domains
laxtic.com
web.dev.428lab.net
adapptt.com
mb.almeraim.com
www.altintopsarraf.com
angliacp.co.uk
ape.haus
arcanacore.tech
www.atlassensor.com
get.bacromana.com
tracking.dev.beefast.eu
www.bkhydraulicsindia.com
boucherie-philippe-gerel-lamballe.fr
brilliant.ac
api.buscuu.com
www.portal.capturemeters.com
cfranklin.space
www.cirus.mx
prod.clevernet.app
clerk.cloud-terminals.com
cloudcioservices.com
www.corequ.com
coversim.net
www.dedy.no
cf.prod.mun.delcom.nl
www.dominicanuniversitycamps.com
task.dreamepoint.com
pos.easybus.app
emojiappiconmaker.com
jpf.envisageworldwide.com
myvaultspa.gen11project.com
app.glainz.com
grancoramino.live
hongmoe.com
ibdpg.tw
idaerik.se
intel-i-park.com
ssindia.invue-live.com
mta-sts.jimw.ca
www.joose.works
jugarte.es
employer.kukerja.id
www.lawandlegaladvice.com
www.leadifyjobs.com
www.leo-ricci.com
townsquare.madhive.com
mazzeo.io
merveozkaynak.com
michaelmaryanoff.com
dev.microtourney.com
mindmeld.pl
minimalistdiary.com
welcome.misto.hr
monmoy.com
www.mr-heritage.name.ng
nanciconsultora.com.br
psqlab.neetigya.me
www.nftpause.io
nickbrennancartoonist.co.uk
nuestrabodajyn.com
sikatan.ktnglangu.or.id
dashboard.otech.events
outomake.com
www.outomake.com
claroclub.pentcloud.com
philbaylog.com
www.pompilhakids.com.br
pereklasty.pp.ua
covid-screening.quadprep.org
auth.rambox.app
runekekonsult.se
prod-new.s-learning.co.uk
www.sanawa.co
www.savoirvivrecosmetics.com
messaging.app.shah2range.com
www.shamudeen.ca
go.showzone.io
parent.devy.skool.sg
www.skylinepropertiess.com
www.stastech.be
steed.tw
pos.sterve.shop
superclusterbakery.com
taifme.com
x--dev.tayl.app
royalbus.tcontur.pe
www.thalystory.com
www.therealnews.in
auth.thicc18.com
www.troim-adv.com
apolo.turnosweb.app
unifiedmind.org
gfh-mobile-app-privacy-policy.upgraide.ai
shop.villasilvasolidale.org
vishalchhatwani.com
vscanimaging.com
wardrobeway.app
preprod-call-hector-widget.wattless.fr
www.workthetrades.com
zxcnews.com
Other domains in certificate