77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.geotech.mx
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 25, 2025
Valid Until
February 23, 2026 86 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
96:7F:B0:96:9C:40:A0:C5:1C:8D:2F:6C:5F:60:B2:D7:AC:04:47:C4:99:73:A0:82:5F:A7:8C:57:8E:F5:81:71
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
non-engineered-ballast-tool.textiles.org

Other domains in certificate

6565.chatbot.gallery
98tank.com
belohradsky.alphai.cz
www.andreacampaci.it
firebase2.andytruong.dev
ariacafe.co
bb-nails.com
experiences.benguelacove.co.za
app.bimgarden.net
discount.bitcoinbabies.com
www.borsetti.sg
app.boxup.io
suntory.cantara.io
rook.chekt.com
cnpferreira.com
codecacto.com.br
colormomentsbook.com
cowerkerz.com
asoblockchain.cryptopayment.link
auth.deckofcards.net
demo-corporate-website.dee-studio.com
www.deepakshankar.com
dentistwarilla.com.au
dermaestetic.de
fb.dogstarphoto.co.uk
q3-mypreferences.dpdlocal.co.uk
dev.retail.easygolf.vn
smart-home.edgetech.am
central.edpc.dev
emolab.app
www.ffmrewards21.com
dashboard.flyingeagleonline.in
app.fruitful.ag
futureit.si
fuud.menu
galineer.com
www.geotech.mx
dashboard.gezibilen.com
sky.golfpass.app
gosearch.xyz
graybord.com
www.innocens.be
www.intelligibleharmonics.com
invoctopus.com
www.ismcorpprogram.org
jasminearmstrong.co
beta.your.karma.life
legere.news
articles.liberty-tips6.com
www.makina-auto.com
marc-steele.com
residentparks.melbookings.com
www.mike-ringel.de
mistergreenlease.fr
mountainwestappraisers.org
www.musicmoving.com
ulem.my.id
www.nodointel.com
links.notifya.app
novila.xyz
ofertasmogi.com.br
okamolife.net
ollivere.co
revamper.osr.solar
personalovertagande.se
www.phdbydesignsearch.com
streetbangkoketiennemarcel.order.pulp.eu
qurtuba.space
www.r4restart.com
it.radioplayer.app
reidacess.ng
perintis.rumahamal.org
www.sitecraft.io
beam-qa.skykit.com cms-stage.skykit.com
fotofinish.soaq.co
unified-wealth.solerabank.com
blog.sprintso.com
www.steelspace.io
link.steps.app
superticket.gr
telana.xyz www.telana.xyz
db.theaterkino.net
traffx.space
qr.trasladossls.com.ar
mdzcdm.turnosweb.app
receptie.mojo.una.events
memu.uncannyvalley.com.au
www.viasavona56.com
torneo.voleibolrivas.es
vooks.io
www.voxlabs.io
www.vthaiasset.com
www.wettbewerbsforum-bahn.de
clc.whyq.com.au
windai.studio
nyateti.zlfzx.xyz
dev.zxor.mx