80/100 SECURITY SCORE

Certificate Information

Subject
CN=images1.mail.servecake.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 12, 2025
Valid Until
March 12, 2026 54 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9B:DC:8F:45:CD:7F:28:55:A0:50:40:08:51:94:24:B8:31:15:DF:16:4E:BD:10:E5:2D:45:AA:6F:E0:C5:7D:6B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

78 domains
app.servecake.com app2.servecake.com appdirect.servecake.com ca.servecake.com dev.servecake.com internal.servecake.com luxcloud.servecake.com mail-ovh.servecake.com mail.servecake.com prod-mail.servecake.com stg-mail-ovh.servecake.com telekomcloud.servecake.com us-staging.servecake.com us.servecake.com we.servecake.com agencesecrete.mail.servecake.com appdirect2.app.servecake.com aspen-epsilonemailsolutions.mail.servecake.com devenv.dev.servecake.com dmsconnect.mail.servecake.com elbenwald.mail.servecake.com endusers.us.servecake.com epsilonemailsolutions.mail.servecake.com flymail.mail.servecake.com helloweb.mail.servecake.com images1.mail.servecake.com innsolu.mail.servecake.com int40.dev.servecake.com internal.internal.servecake.com k2telecom.mail.servecake.com kirjekyyhky.mail.servecake.com luxcloudtemp.luxcloud.servecake.com mdconnected.mail.servecake.com mtncloud.mail.servecake.com mtncloudfrench.mail.servecake.com neolo.mail.servecake.com opendigital.mail.servecake.com patrick.dev.servecake.com pixelcircus.mail.servecake.com readerimpact.mail.servecake.com risemedia.mail.servecake.com simplesms.mail.servecake.com squiddd.mail.servecake.com staging.mail.servecake.com static1.mail.servecake.com untapped.mail.servecake.com users.app2.servecake.com willem.dev.servecake.com wimg.mail.servecake.com adhoc.aspen-epsilonemailsolutions.mail.servecake.com agencesecrete.agencesecrete.mail.servecake.com aspen.epsilonemailsolutions.mail.servecake.com biznet.squiddd.mail.servecake.com canvas.untapped.mail.servecake.com devenv.patrick.dev.servecake.com devenv.willem.dev.servecake.com dmsconnect.dmsconnect.mail.servecake.com elbenwald.elbenwald.mail.servecake.com endusers.images1.mail.servecake.com endusers.static1.mail.servecake.com flymail.flymail.mail.servecake.com french.mtncloud.mail.servecake.com helloweb.helloweb.mail.servecake.com innsolu.innsolu.mail.servecake.com int40.int40.dev.servecake.com k2telecom.k2telecom.mail.servecake.com kirjekyyhky.kirjekyyhky.mail.servecake.com luxcloudtemp.images1.mail.servecake.com luxcloudtemp.static1.mail.servecake.com mdconnected.mdconnected.mail.servecake.com neolo.neolo.mail.servecake.com pixelcircus.pixelcircus.mail.servecake.com risemedia.risemedia.mail.servecake.com simplesms.simplesms.mail.servecake.com squiddd.squiddd.mail.servecake.com telekomcloud.images1.mail.servecake.com telekomcloud.static1.mail.servecake.com wimg.wimg.mail.servecake.com