76/100 SECURITY SCORE

Certificate Information

Subject
CN=onegeorgefox.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 28, 2026
Valid Until
August 26, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:6F:48:10:A9:E6:B8:87:01:EA:A0:47:1E:77:B1:59:BE:AD:6E:1B:04:59:0F:CF:64:29:4A:A9:F1:E4:D3:CC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
merreell.com *.merreell.com *.ci.merreell.com *.development.merreell.com *.poc.merreell.com *.preprod.merreell.com *.ww25.merreell.com

Other domains in certificate

adstikung.online *.adstikung.online
beaverchoice.com *.beaverchoice.com *.becekitchen.beaverchoice.com *.crazydumplingshack.beaverchoice.com *.hannaplaceusa.beaverchoice.com *.hannasemail.beaverchoice.com *.hannasplaceusa.beaverchoice.com *.hotfix.beaverchoice.com *.mail.beaverchoice.com *.meatpressusa.beaverchoice.com *.meatspressusa.beaverchoice.com *.pierogiarizona.beaverchoice.com *.random.beaverchoice.com *.shelfcenter.beaverchoice.com *.staging.beaverchoice.com *.test.beaverchoice.com *.ww16.beaverchoice.com *.ww17.beaverchoice.com *.www.beaverchoice.com
*.api.executivejobs.it *.backend.executivejobs.it executivejobs.it *.executivejobs.it *.staging.executivejobs.it
gnes.com *.gnes.com *.mail.gnes.com *.talents-accompa.gnes.com *.ww25.gnes.com *.ww38.gnes.com
*.17.hanime1.cc hanime1.cc *.hanime1.cc *.website.hanime1.cc *.ww17.hanime1.cc *.ww19.hanime1.cc *.ww25.hanime1.cc
*.api.lanzhou.it *.backend.lanzhou.it *.demo.lanzhou.it *.hostmaster.lanzhou.it lanzhou.it *.lanzhou.it
onegeorgefox.org *.onegeorgefox.org *.www.onegeorgefox.org
thebestjob.it *.thebestjob.it
toclub.it *.toclub.it
*.affiliates.tyroodr.com *.bi.tyroodr.com *.cdn.tyroodr.com *.cdnimages.tyroodr.com *.et.tyroodr.com *.it.tyroodr.com *.rep.tyroodr.com *.ret.tyroodr.com *.srv.tyroodr.com *.static.tyroodr.com *.stockwerk23et.tyroodr.com *.superset.tyroodr.com *.tcwiki.tyroodr.com tyroodr.com *.tyroodr.com *.ws.tyroodr.com *.wss.tyroodr.com
*.analytics.usus.it *.apps.usus.it *.heip.usus.it *.hostmaster.usus.it *.lat.usus.it *.secure.usus.it usus.it *.usus.it
vinagreta.it *.vinagreta.it
vivamilano.it *.vivamilano.it