Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=fortydegreewaters.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 25, 2026
Valid Until
April 25, 2026 83 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
47:16:69:67:0C:5D:B6:67:ED:D5:C3:47:BD:4C:53:EA:29:09:84:77:19:E2:38:66:86:A1:1D:29:90:EC:EE:29
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
metaforma.ca

Other domains in certificate

2ndwavewasteservices.com
abhrp.com
rc.material.angular.io
ardeche-encheres.com
arovation.com
app.askclass.org
astateofcardboard.com
astrocom.space
www.benfencap.com
bigbentour.com
binosaur.ai
www.birbli.com
bit-fog.com
web.dev.bizflex.app
bricksgta.ca
chlcharts.ca
bulletins.churchstreamer.org
clashfy.com.br
clothchord.com
colorexpander.com
corpnco.com
hub.cosmogenesiscomunidad.com
coursesync.ca
www.derrq.com
diamondeastcoatings.com
doo.monster
www.drakensol.com
drumaid.com
drumlessonsedinburgh.com
dxv.ai
edwinbodgepottery.com
expeditelaw.co.uk
fasublimacoes.shop
fortydegreewaters.com
franquetagency.com
ru.freebtc.it
geoz.ai
www.getturn.app
gobbas.it
goldengateguide.com
www.groove-l.app
hassanfilms.com
www.hymngarden.org
alfred.isurf.app
protocitysim-dev.jonaswills.com
kauthukam.live
www.knotguide.app
www.lfky.app
www.love-all-serve-all.org
www.melaniereeves.com.au
monprojectlocatif.fr
neuralilux.com.br
api.neurosity.co
crocodile.nfc-clothing.app
www.nolag.app
auth.opentrain.app
pomoc-drogowa.ostrowiec.pl
chronos.paradowski.site
dev.paralam.ca
www.pattyhendrix.ninja
patwardhanmed.consulting
www.phyxsi.us
dev.app.polyflow.co
practicalweb.co.uk
link.prayermatch.org
pukloo.fun
radiochr.be
app2-stage.raveretailer.com
cpanel-apex.rcloudsoft.app
superm2.react-tutorial.app
rehablytics.ca
app.revboostapp.com
romethod.net
auth.run.place
santengenharia.com.br
sellstack.app
auth.sexysexy.ai
www.smartautismbarta.org
solsi.com.br
juego.somosmelo.co
surambika.com
superblast.games.tetherstudios.com
thenewsintwos.app
www.thercc.us
sandbox.reapitapp.thirdfort.com
gupshup.tichkolay.online
social.tigweb.org
link.dev.tilt.app
www.trysteady.app
www.unicornshift.ai
urlmaps.com
auth.vendorone.io
www.viniepecorini.it
ps.vyro.ai
www.welsheducation.com
www.wescore.ai
login.westsprucecreekdatabase.org
matrizes.yatto.com.br
yunikon.no