86/100 SECURITY SCORE

Certificate Information

Subject
CN=eu-feeds.zohoconnect.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 23, 2026
Valid Until
June 21, 2026 49 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
61:D8:E0:D0:E9:51:33:F5:07:3F:B4:30:A1:01:EF:82:C3:40:F3:6E:9D:8B:02:65:B7:3D:A2:B0:75:FF:B5:B8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=64072000; includeSubDomains; preload
Content-Security-Policy
Basic
script-src; connect-src; frame-src Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

57 domains
mailer.zohoapi.eu notifications.zohoapi.eu payments.zohoapi.eu

Other domains in certificate

eumail.finepick.com
feedback.sdpondemand.eu
notifications.zappsusercontent.eu
eu-notifications.zoho-inventory.com eu-sender.zoho-inventory.com
eudirectory.zohoaccounts.com eudmailer.zohoaccounts.com eumail.zohoaccounts.com euportal.zohoaccounts.com
eu-notifications.zohobooks.com
eu-notifications.zohocalendar.com
eu-mailer.zohochat.com eu-notification.zohochat.com
eu-feeds.zohoconnect.com
eu-mailer.zohocrmplus.com
eu-notifications.zohoexpense.com
eu-notifications.zohoinvoice.com eu-sender.zohoinvoice.com
eu-mail.zohomotivator.com
eu-notification.zohonotebook.com
mailer.zohoofficeapi.eu notifications.zohoofficeapi.eu payments.zohoofficeapi.eu
info.eu.zohoprojects.com notifications.eu.zohoprojects.com productmails.eu.zohoprojects.com
notifications.eu.zohorecruit.com sender.eu.zohorecruit.com
eumail.zohoreports.com eumail1.zohoreports.com
eumailer.zohosalesiq.com
euaudits.zohosearch.com
notifications.zohosheet.eu
eu.notify.zohoshow.com
eu-mailer.zohoshowtime.com
internal.zohosites.eu mailers.zohosites.eu portal.zohosites.eu users.zohosites.eu
eu-mail.zohosocial.com eu-usermail.zohosocial.com
mailer.zohosprints.eu
eu-notifications.zohosubscriptions.com eu-sender.zohosubscriptions.com
eu-app.mailer.zohosupport.com eu-service.mailer.zohosupport.com
eu-surveytransmail.zohosurvey.com eu-surveytransmailuser.zohosurvey.com
surveytransmail.zohosurvey.eu surveytransmailuser.zohosurvey.eu
notifications.zohovault.eu
mail.zohowiki.eu
zwntrmail.zohowriter.eu zwtrmail.zohowriter.eu