76/100 SECURITY SCORE

Certificate Information

Subject
CN=agartalainsurance.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 09, 2026
Valid Until
May 10, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B4:73:AA:7C:5E:26:AE:8A:E8:4D:05:8D:6B:5B:C7:01:98:BA:59:A4:26:21:BD:3F:D8:0E:D5:03:CF:A4:B7:E7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
staiger.com *.staiger.com *.anyconnect.staiger.com *.api.staiger.com *.app.staiger.com *.autodiscover.staiger.com *.ciscoasa.staiger.com *.cloudvpn.staiger.com *.connect.staiger.com *.crm.staiger.com *.customers.staiger.com *.dashboard.staiger.com *.dev.staiger.com *.email.staiger.com *.ftp.staiger.com *.gp.staiger.com *.imap.staiger.com *.leads.staiger.com *.mail.staiger.com *.ns.staiger.com *.portal.staiger.com *.ra.staiger.com *.random.staiger.com *.ravpn.staiger.com *.relay.staiger.com *.remote.staiger.com *.sales.staiger.com *.secure.staiger.com *.sitemap.staiger.com *.sitemaps.staiger.com *.smtp.staiger.com *.ssl.staiger.com *.sslvpn.staiger.com *.support.staiger.com *.test.staiger.com *.vpn.staiger.com *.webmail.staiger.com *.ww1.staiger.com *.ww16.staiger.com *.www.staiger.com

Other domains in certificate

agartalainsurance.com *.agartalainsurance.com *.app.agartalainsurance.com *.insights.agartalainsurance.com
*.api.qqux.com *.backup.qqux.com *.dev.qqux.com *.ekeca.qqux.com *.hifsx.qqux.com *.jwio.qqux.com *.lfmkp.qqux.com *.m.qqux.com *.out.qqux.com qqux.com *.qqux.com *.sirh.qqux.com *.test.qqux.com *.ukguj.qqux.com *.zfl.qqux.com
*.api.saveings.com *.crm.saveings.com *.dev.saveings.com *.lime.saveings.com *.mail.saveings.com saveings.com *.saveings.com *.sitemap.saveings.com
*.api.sonchou.com *.m.sonchou.com *.sitemap.sonchou.com *.sitemaps.sonchou.com sonchou.com *.sonchou.com *.vpn2.sonchou.com *.ww25.sonchou.com
*.api.soubise.com *.i88.soubise.com *.mail.soubise.com *.s23.soubise.com *.sitemap.soubise.com soubise.com *.soubise.com *.test.soubise.com *.web5725.soubise.com *.ww16.soubise.com
*.api.super.hospital *.sai.super.hospital super.hospital *.super.hospital