76/100 SECURITY SCORE

Certificate Information

Subject
CN=pradoverde.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 13, 2026
Valid Until
May 14, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8B:1E:2D:7B:36:EC:15:64:FD:77:B8:54:0C:74:EE:3F:15:48:4C:1F:90:B6:24:9A:80:9A:06:C5:E4:B9:53:78
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
pradoverde.com *.pradoverde.com *.api.pradoverde.com *.backup.pradoverde.com *.dev.pradoverde.com *.mail.pradoverde.com *.sitemap.pradoverde.com *.sitemaps.pradoverde.com *.test.pradoverde.com *.ww1.pradoverde.com *.ww16.pradoverde.com *.ww17.pradoverde.com *.ww25.pradoverde.com

Other domains in certificate

*.82a40fe0-54a5-4ce3-bcb5-93a25789b775.cerume.com *.acceso.cerume.com *.access.cerume.com *.admin.cerume.com *.anyconnect.cerume.com *.api.cerume.com *.app.cerume.com *.apps.cerume.com *.autodiscover.cerume.com *.blog.cerume.com cerume.com *.cerume.com *.citrix.cerume.com *.clientesvpn.cerume.com *.cloudapp.cerume.com *.connect.cerume.com *.desktopstudent.cerume.com *.gateway.cerume.com *.hostmaster.cerume.com *.kmwacremote.cerume.com *.labvirtual.cerume.com *.log.cerume.com *.m.cerume.com *.mail.cerume.com *.members.cerume.com *.mobileconnect.cerume.com *.mta-sts.cerume.com *.notexistsblog.cerume.com *.officevpn.cerume.com *.ordpress.cerume.com *.portainer.cerume.com *.portal.cerume.com *.random.cerume.com *.rds.cerume.com *.rdweb.cerume.com *.receiver.cerume.com *.remote.cerume.com *.remoteaccess.cerume.com *.remoto.cerume.com *.rhuxords.cerume.com *.secure.cerume.com *.ssl.cerume.com *.sslvpn.cerume.com *.stg.cerume.com *.store.cerume.com *.studentsvpn.cerume.com *.ts.cerume.com *.vdi.cerume.com *.vpn.cerume.com *.vpn2.cerume.com *.vpnssl.cerume.com *.webtest.cerume.com *.webvpn.cerume.com *.wordpress.cerume.com *.www.cerume.com
*.adg.deliverymoretimes.info deliverymoretimes.info *.deliverymoretimes.info *.doh.deliverymoretimes.info *.hare.deliverymoretimes.info *.m.deliverymoretimes.info *.mail.deliverymoretimes.info *.ncdn.deliverymoretimes.info *.ns.deliverymoretimes.info *.remote.deliverymoretimes.info *.resolver1.deliverymoretimes.info *.share.deliverymoretimes.info
*.files.jgroupadvertising.com jgroupadvertising.com *.jgroupadvertising.com *.mail.jgroupadvertising.com *.mailer.jgroupadvertising.com *.owa.jgroupadvertising.com *.rds1.jgroupadvertising.com *.sleipnirlogiwww.jgroupadvertising.com