Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=idoz.salai.co.il
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
May 06, 2026
Valid Until
August 04, 2026
74 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A9:D0:CB:A4:F4:B9:A5:21:6B:A9:3D:DF:31:52:1A:88:58:5E:DB:0D:80:42:76:7F:1F:E7:29:B4:B5:4E:3C:17
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
pladsate.com
scp-mobile-test.3dcloud.io
4o2.io
calculei.agrimind.com.br
www.aguayplantas.com
aitoolbar.in
www.akurlaev.com
alessandravalle.lat
anelisateixeira.adv.br
apostrophes.studio
aquacalcaire-enr.com
arunaidroptaxi.com
www.ashrafpower.mom
balagtravellersandtaxies.online
www.balahomesthirukadaiyur.com
www.stats.baseball-connections.com
betonni-kiltsia-lviv.shop
bgx.solutions
bookhousedelhi.com
broadleafdigitalsolutions.co.uk
www.bufetexpromosyon.com
chugunovlogistics.ru
www.clarity.nz
clayweidinger.com
conviteai.com.br
www.cornerstonechurchonthepark.org
croppyllc.com
certificate-b2c.csspl.info
davis4worcester.com
www.earbutarediocese.org
sosparebriseplus.app.effiquo.com
mental-sleep-sdm.elservice.cc
fabricaatitude.com.br
news.foxiomleads.com
tattersall.fullmec-chile.cl
goiartec.com.br
gset.ai
www.gset.ai
hakobune-child.com
beta-app.handcash.io
dev.delete-me.hark.eco
db.holoplayer.jp
uat2-egat.houseofdev.tech
i1an.xyz
indigoworks.com.br
jakub-gaska.pl
www.javatheory.net
link.joule.video
lasvegasoffmarketproperties.com
cv.le-dev.com
www.likegle.com
lochassist.co.uk
app.luckybombcasino.com
www.manippoudel.com
www.mathsbridge.ma
www.rene.mccaine.me
pianobraille.miguelbernal.xyz
heygen.mnkjoshi.ca
app.mytraineros.com
auth.nextsong.live
noahfreelove.com
www.ofcollabmap.com
owners-client.info
www.pingpong-tech.com
letshine.piticommerce.com
www.policysmart.in
printers.hu
www.protechsign.com
quencode.io
querent.xyz
quicklitrack.com
quickmain10.com
www.righardbrink.com
rockriverbrewingcompany.com
rocsch.com
idoz.salai.co.il
www.sazposh.com
embed.sceneopsis.com
www.sellfirst.tech
www.shanmukhadataai.com
pronto.sisidev.com
sooho.info
sorashin.com
admin.stayzee.co
evaluator.studygazelle.com
suncheon-hillstate.kr
www.taucapitales.cl
www.thearchmate.com
thegreyboard.uk
triplewhale.titanpowerplus.com
tiwaoil.ly
www.tubebite.site
staging.backoffice.ulearn.study
www.visyt.tech
www.voxelcubes-games.com
www.webura.se
wisalnmiri.online
woodofmetal.com
download.yatrirailways.com
akankshaportfolio.zootem.com
Other domains in certificate