Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=carharttwipdeutschland.de
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 19, 2026
Valid Until
August 17, 2026 57 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
14:EC:C2:4B:4E:01:B8:38:B5:A5:C1:E9:11:5E:B3:6E:50:4C:06:96:C7:3F:71:B3:CC:B9:12:FB:A7:32:D0:96
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
podhale.de *.podhale.de

Other domains in certificate

1of9.io *.1of9.io *.app.1of9.io *.chat.1of9.io *.cpcalendars.1of9.io *.demo.1of9.io *.media.1of9.io *.shop.1of9.io *.www.1of9.io
adaptableindia.com *.adaptableindia.com *.binary.adaptableindia.com *.level.adaptableindia.com *.repurchase.adaptableindia.com *.singleleg.adaptableindia.com
*.a.autoelitelucidatura.com autoelitelucidatura.com *.autoelitelucidatura.com *.git.autoelitelucidatura.com *.mail1.autoelitelucidatura.com
carharttwipdeutschland.de *.carharttwipdeutschland.de
*.bimatap.directline.co directline.co *.directline.co *.okta.directline.co *.selfservice.directline.co *.ww25.directline.co *.ww38.directline.co
extra-crypto.com *.extra-crypto.com
*.email.findaspa.com findaspa.com *.findaspa.com
*.emv1.geographylessons.us geographylessons.us *.geographylessons.us *.mail.geographylessons.us
homewares.au *.homewares.au *.ww25.homewares.au
hoshiakaridub.com *.hoshiakaridub.com
*.hmcl.huany.com huany.com *.huany.com
icpr2018.org *.icpr2018.org
marieswrld.co *.marieswrld.co *.ww38.marieswrld.co
*.cpcontacts.olymp20.casino *.dev.olymp20.casino olymp20.casino *.olymp20.casino *.www.olymp20.casino
*.hostmaster.opuesto.com *.m.opuesto.com opuesto.com *.opuesto.com *.ww16.opuesto.com *.www.opuesto.com
quattroforme.it *.quattroforme.it
*.autodiscover.s44833.com s44833.com *.s44833.com *.sitemap.s44833.com
*.assets.tapplay.co *.gateway.tapplay.co tapplay.co *.tapplay.co
*.eye.tuition.asia *.kafka-preprod.tuition.asia *.m.tuition.asia *.preprod-data.tuition.asia tuition.asia *.tuition.asia *.wap.tuition.asia
*.hostmaster.tveexpress.pro tveexpress.pro *.tveexpress.pro
*.m.uoslmedia.com *.mail.uoslmedia.com *.pgndtcpanel.uoslmedia.com *.remote.uoslmedia.com uoslmedia.com *.uoslmedia.com