78/100 SECURITY SCORE

Certificate Information

Subject
CN=com-cf-redirects-intl.classflow.com
Issuer
C=US, O=Amazon, CN=Amazon RSA 2048 M04
Valid From
November 04, 2025
Valid Until
December 03, 2026 318 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BD:87:89:FE:C2:7B:E4:6B:E7:21:EC:AE:A1:6F:1B:AE:69:AB:80:27:84:3C:3D:75:53:4D:73:76:DD:06:49:A8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

82 domains
acvsd.classflow.com adstl.classflow.com automation.classflow.com avhsd.classflow.com axiedu.classflow.com bahamas.classflow.com bcps.classflow.com beam.classflow.com brhstl.classflow.com browardschools.classflow.com byramhills.classflow.com cfcontent.classflow.com cfisd.classflow.com cfqaprod.classflow.com cfresourcepackprod.classflow.com chascotl.classflow.com chesterton.classflow.com chilestl.classflow.com coalfire.classflow.com com-cf-redirects-intl.classflow.com cps593.classflow.com d11nms.classflow.com dadeschools.classflow.com demo.classflow.com ecisd.classflow.com edisonk12.classflow.com esc20.classflow.com fcboe.classflow.com forsythcotrial.classflow.com forsythk12.classflow.com gac.classflow.com gccisd.classflow.com gis.classflow.com harford.classflow.com hmh.classflow.com holland.classflow.com howard.classflow.com hsd.classflow.com ipsb.classflow.com isd77.classflow.com jmcsspilot.classflow.com knightstl.classflow.com learn.classflow.com lpsstl.classflow.com marketplace.classflow.com matsuk12.classflow.com mcnealtl.classflow.com mdcps.classflow.com moest.classflow.com ncperson.classflow.com ncpsk12.classflow.com newton.classflow.com ops.classflow.com padistance.classflow.com palmdale.classflow.com palmertl.classflow.com partnertraining.classflow.com pilot.classflow.com portsmouth.classflow.com prod.classflow.com psd.classflow.com rennertl.classflow.com salkelementary.classflow.com sarasotacountyschools.classflow.com scotttl.classflow.com scu.classflow.com sjps.classflow.com sof.classflow.com ssc.classflow.com strawnschool.classflow.com swigerttl.classflow.com training.classflow.com uabengelschool.classflow.com usf.classflow.com usfexperience.classflow.com vhs.classflow.com walton.classflow.com warwickschools.classflow.com wcds.classflow.com weightmantl.classflow.com whisperingpines.classflow.com wsfcs.classflow.com