Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.fallacy.io
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 15, 2025
Valid Until
January 13, 2026
47 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A3:64:ED:3F:44:00:4C:37:71:40:2C:8F:56:27:25:ED:32:08:00:65:71:66:7F:54:04:59:50:1E:F9:E5:98:7F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
sandbox.snappers.tv
3boode75.uk
aeroxpertsolutions.com
andrewkelly.xyz
www.arxis-ec.com
budget.baballou.com
auth.badmintonireland.com
www.bbi.id
beatthebeans.de
grizzlysgiesenvolley.deeplinks.bfansports.com
canadavisachacking.com
capital-iq.in
cardsly.be
www.cnergy-solutions.com
animeshmohanty.co.in
bizzlab.co.in
ff.thrivikram.co.in
www.codykit.dev
www.danielosetiawan.com
datamonastery.co.uk
www.deenshippingandmarine.com
dietetyklena.pl
doofenders.com
exif.dyno.design
e-tailer.co.uk
sandbox.admin.earthly.org
esploralibri.com
www.fallacy.io
festfrwrd.dev
stage.link.fmn.chat
taxi.gagantransport.com
daylight.gchouse.org
appjoven.saltillo.gob.mx
develop.gorbotics.com
www.dashboard.growupfund.com
www.halfbloodquince.com
ziele.impactwrap.com
ipdandp.com
www.jaqu.in
values.joinavenir.com
www.keepsafety.pl
marvel.kevcoder.co
lanave.ink
app.languakids.com
www.laughsavers.com
edge.librista.dev
www.mariano-zorrilla.com
meedocument.in
www.acessorios.meuplanoclaro.com.br
mgapsicologia.com
stockcal.minlabz.com
home.miwizz.com
mytargetbank.com
www.app.testnet.nerochain.io
info.new-mobil.de
app-link.nexopay.io
www.nointernetgames.net
ns-souken.com
nurtora.com
wolfgang.order.place
crop-trade-sim.physictype.dev
web.pinaflare.com
www.primeautomotive.ca
demo.quickparentapp.com
sputnik.reachmedia.co.nz
saravananns.com
send2hr.xyz
senithek.com
dev-points.serban.pw
www.shutterfly.studio
randompass.sid426.dev
singinglessonsdublin.com
olj.siwa.io
spacetimerust.com
www.spotcatalog.com
sreeharir.com
stage.storyplace.com
community-staging.synctalk.us
tanzraume.com
zebiestudios-pinata.teraception.com
www.thainesesolutions.com
evolutionary.theorygenerator.com
dev.thepocketdogtrainer.com
www.thomasdupre.fr
topslot777.com
mobiletrato.trato.io
node-hcqa.travizory.ch
www.triventcad.com
www.uebeleis.at
vegstreak.co.uk
booking.visitnadabet.com
links.vocsong.com
my.vokno.ru
links.well-beam.com
dashboard.wenergie.io
winkkee.fr
world-clock.com
zenovisuals.com
mdcall2020.zinglio.com
znheck.co
Other domains in certificate