Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.opticalbrightener.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 19, 2025
Valid Until
December 18, 2025
34 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
10:D3:FF:11:12:D8:9B:3F:3D:B2:3A:F0:1E:E4:B6:EB:B7:CE:3C:4E:1E:41:F7:FE:DB:A8:A8:9F:D3:54:D3:D7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
publiferocks.com
www.1percentlabs.com
ahcees.com
albums.311.com
petrel.amrgharieb.com
www.andrericard.dev
www.andrewf.net
arraysocial.mx
www.askvery.com
bulgaa.dev
buymeacoffee.in
candiceai.co.za
clientes.cimsw.com.br
beta.cittyo.com
clinic.mvrc.co.in
all-in-one-bravo-link-uat.generali.com.hk
testbed.dashboard-y.app
datanest.jp
mobile.daypepper.com
dev.digiqc.com
digitaltreasury.fund
lp-gen.digitorm.com
dispenx.com
domotica-peru.com
swipe.duaneleong.com
www.echardingergartenlaube.de
www.ecounselingconnection.net
classroom.edyant.com
apidocs.embdeals.com
erez-dayan.com
ettlin.io
test.finncub.com
gbear.trade
geethadroptaxi.in
goodcounselliffeygaels.ie
www.goquickbox.com
happybox.buzz
inspection.harecord.com
travel.horizonteparalelo.com
hoteldenta.com
www.hotelsearockvilladaman.com
blog.iamkishorekumar.in
iantomarcello.com
ipsv.dev
it-consulting-wangler.de
www.jedatu.com
home.jogo-app.com
enterprise.joulebug.link
test.kiallaknightscricketclub.com
www.kinebalanced.be
kyrios.dev
lineups.in
blog.loriedo.com
lualearning.org
madhouse.ag
io.marcafranca.com
marcusphillipswatson.com
www.mazuryatl.com
mediapilvi.fi
www.melba-pro.com
meropoolservices.com
care.merustaging.com
mifillosophy.com
morfocus.com
muontelescope.com
www.mywellness-coach.com
entidades.nhecotech.com
landing.nishkal.in
old.omichi-naruto.com
oneconsultant.ae
www.opticalbrightener.com
prophantasiatrainer.com
dialer.qlu.ai
www.ra1phspencer.com
www.relationshiphero.com
reviza.info
url.ridewithvia.dev
rissell.me
www.sashasabherwal.com
savannahmartinez.com
soccerpredicts365.com
dev-dynamic-link.soundadvice.ai
stratumgp.com
studyhubs.in
swichdesign.com
snowball.synhayden.com
tabberry.com
tcgp-trading.com
www.thymebook.com
tinhlaisuatkep.com
trd-ai.com
unnon.com
usedebo.com.br
staging.utm-boss.com
verbundance.com
vitaello.es
vovapy.com
admin.waldsolutions.com
api-service.wecovr.com
staging.winston-analytics.com
Other domains in certificate