Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E8
Valid From
March 07, 2026
Valid Until
June 05, 2026
35 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
64:FC:5B:ED:5A:15:CA:75:AF:01:26:AC:1D:A8:83:45:B3:DE:4D:A1:EE:42:C1:06:AF:FF:46:93:97:11:1E:C5
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
51 domains
rarelyvt.com
www.aurinavenir.co.uk
tls.automattic.com
bessparker.com
www.bessparker.com
bistrots.net
www.bistrots.net
dannykadum.art
dax.tips
www.dax.tips
glo-skinstudio.com
harshitsingh.link
www.harshitsingh.link
loladescours.com
mainefoic.org
maisonvane.com
www.maisonvane.com
how-to-clear-cache.nigeljoy.me
nseaa.ca
www.nseaa.ca
psb.pe
www.psb.pe
raeaviani.com
www.raeaviani.com
www.rdlbarton7.com
rebrown.blog
www.rebrown.blog
rfacall.com
www.rfacall.com
rhymenchatt.org
www.rhymenchatt.org
rioiro-log.com
seniorsoftballwomen.org
sirtimf.com
www.tennanthumesfortasd.com
thedarknesses.com
www.thedarknesses.com
thedigitalfifth.com
www.theoneandonlymichaelemond.com
www.thepursuitofhappinessnoz.com
www.theravenfile.com
thermovisiontech.com
www.thginketihw.com
thiloyoung.com
www.thinkingpop.com
thismomshitiswild.com
www.thismomshitiswild.com
www.thissingleindividual.com
tigramstrategies.com
www.tigramstrategies.com
www.timraez.com
Other domains in certificate