86/100 SECURITY SCORE

Certificate Information

Subject
CN=notifymw.zoho.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
November 10, 2025
Valid Until
February 08, 2026 59 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C2:58:CE:CC:F9:B3:A2:18:3A:D5:B5:21:08:47:D5:12:9E:4F:48:7C:C1:93:3B:B3:A1:75:BD:93:7A:FE:3B:83
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=64072000; includeSubDomains; preload
Content-Security-Policy
Basic
script-src; connect-src; frame-src
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

97 domains
mail.site24x7sp.com

Other domains in certificate

mail.alarmsone.com
mail.finepick.com
routeiq.com www.routeiq.com
notifications.salesinbox.com sender.salesinbox.com
feedback.sdpondemand.com
mail.site24x7.com
accounts.thandora.com notifications.thandora.com payments.thandora.com
demo.transmail.com notifications.transmail.com
mailer.zconfirmation.com
mailer.zinvitation.com
notifications.zoho-inventory.com sender.zoho-inventory.com
mailer-lp.zoho.com mailer-tu.zoho.com mobile-transmail.zoho.com mproxy-transmail.zoho.com notification-kms.zoho.com notification.bugbounty.zoho.com notifications-sd.zoho.com notifications.antivirus.zoho.com notifymw.zoho.com search360alerts.zoho.com zurs.zoho.com
directory.zohoaccounts.com dmailer.zohoaccounts.com mail.zohoaccounts.com mailer.zohoaccounts.com portal.zohoaccounts.com smailer.zohoaccounts.com
productmails.zohoappcreator.com usermails.zohoappcreator.com
e.zohoassist.com info.zohoassist.com notification.zohoassist.com user.zohoassist.com
zohoblockchain.com
info.zohoblueprint.com mailer.zohoblueprint.com notifications.zohoblueprint.com
notifications.zohobooks.com sender.zohobooks.com
wms.zohobusiness.com zohobusiness.com
notifications.zohocalendar.com sender.zohocalendar.com www.zohocalendar.com zohocalendar.com
zohocampaign.com
mailer.zohochat.com notification.zohochat.com zohochat.com
mail.zohocheckout.com notifications.zohocheckout.com
mail.zohoconnect.com mailbot.zohoconnect.com me.zohoconnect.com
usermail.zohocontactmanager.com
mail.zohocontacts.com zohocontacts.com
teammail.zohocreator.com
help.zohocrm.com
mailer.zohocrmplus.com www.zohocrmplus.com zohocrmplus.com
product.zohodeluge.com team.zohodeluge.com usermail.zohodeluge.com
www.zohodirectory.com zohodirectory.com
mail.zohodiscussions.com
zohodocs.com
internal.zohodrive.com notifications.zohodrive.com
customermails.zohoeventz.com
notifications.zohoflow.com
www.zohohost.com zohohost.com
users.zohomeeting.com
zohonimbus.com
admin.zohopagesense.com
notifications.zohosign.com
surveytransmail.zohosurvey.com surveytransmailuser.zohosurvey.com
zohotables.com
www.zohoworkplace.com
admin.zohowriter.com insights.zohowriter.com notification.zohowriter.com zwntrmail.zohowriter.com zwtrmail.zohowriter.com
zpindia.com