SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Expired Certificate - the server's certificate has expired
Open
Cached
·
just now
62/100
SECURITY SCORE
Certificate Information
Subject
CN=dashboard.sendgate.net
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
March 14, 2025
Valid Until
June 12, 2025
Expired
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2C:61:70:25:14:C4:80:1C:E2:1C:29:FE:4F:AA:AF:9F:C0:4C:4C:6A:F8:90:54:AD:8F:58:76:75:4D:56:E8:0F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
rnsk.app
11.shop-online.app
21.shop-online.app
www.8vanced.com
www.app.adminpanel.no
www.analitica.pro
andydarr.dev
www.asociacionsilbogomero.org
athbase.com
www.athlete.athlyts.com
imp.autolm.com.br
awvn.avr.app
www.beasnl.in
buildexcellence.co.za
web.buspal.net
pdf-viewer.chromex.io
here2smile4users.co.il
appadmin.mayka.co.in
www.datalights.co.in
costareal.com.gt
cockpit.lista.com.tr
curtiscali.dev
workshop.dancercise.in
danimate.net
links.qa.digicash.tv
accounts.digitalstrom.com
dolcedaniels.com.mx
www.dolcedaniels.com.mx
seed.partner.ebusaka.com
engenhariadoapp.com.br
www.ericlo.dev
historiaclinica.etereafisioestetica.com
www.feelcoffee.com
finavia.fi
www.firstklaz.live
montfortinternaat.flockim.com
staging.getrentline.com
www.globaldiamondcenter.com
staging.news.goaudio.ai
www.gpibh.com
www.headlandconsulting.co.uk
tools.hoxbycollective.com
www.hugoelizandro.com
io2.inc.nyc
app.infogo.com.br
www.purecollectiveswebdev.innogrp.com
kiosk.insyncapp.io
www.interagent.pl
nida-pajar.itsyourdayofficial.com
sms.jpbsolutions.in
www.kalpenergiasolar.com.br
www.kulabu.dk
www.landgrab.dev
lcrd.in
leolandreville.com
loltheory.gg
www.mbf-llc.com
app.mealhero.me
www.mercaditosobreredes.com
mirrorfuture.online
promo-indihome.my.id
www.nekoneko.tokyo
sitara.nidri.page
nival.me
noppakun.app
sheets.nowdraft.com
ckhospital.omniworks.io
www.pcurrier.com
volks.pecas2b.com.br
demo-control.picks.com.br
www.pilvia.work
www.porvilla.es
previsy.com
vanessa.reip.at
video-search.roboflow.run
www.scorpiancrackers.com
dashboard.sendgate.net
s.sese.dev
www.shortfinsoftware.com
sixbikers.com.br
slip.828.tokyo
sylvia.com.br
app.tallyfour.com
technicflow.com
www.thebusinesssprint.com
app.thumaminadelivery.co.za
calendar-sample.tikedev.com
project.tinkersprojects.com
www.tkvelmos.ru
www.tnnz.io
www.tradertorch.com
app.travzu.com
usamabinshafqat.com
privacy.wiim-research.de
devis.yacinelaribi.site
www.yahyazini.com
budtomorrowland.yesmkt.net
caricometroucal.yesmkt.net
manhazitosregressoaulas.yesmkt.net
www.zezebutikpasta.com
Other domains in certificate