Open
Cached
·
just now
80/100
SECURITY SCORE
Certificate Information
Subject
CN=app.durancoffeestore.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 13, 2025
Valid Until
March 13, 2026
57 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D9:84:19:58:AD:40:64:DA:B7:B2:20:96:D7:6B:C3:EF:D2:B6:A7:84:EE:A9:AB:34:E9:19:F5:70:77:CA:41:8F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Wildcard CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 4 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
Subject Alternative Names
100 domains
sec-hat.com
www.aangan.space
amika.chat
omvpreview.apollo.ai
www.avacon.com.br
play.bitmates.io
www.bitmates.io
brilloextremovm.com
staging.caraer.com
auth.clairia.app
simpletpa.clockwork.ws
www.scriptlab.co.in
cristhianveal.dev
www.dagvandeanimator.be
cdn.dcod.com.br
www.dcod.com.br
auth.dentallabguru.com
www.donkey.business
www.doubleslipper.com
app.durancoffeestore.com
www.ecogroovi.com
staging.everpesa.com
go.exp1.org
timesheet.exp1.org
www.fetego.com
www.fireview-webbase.com
www.firstareaph.com
preview.flowmo.design
www.frastas.com
www.freewateratairports.com
www.fwdcap.com
gasify.ai
catposd.goyirunway.com
dev.gymstreak.com
admin-lotto.hanoiasean.com
hit.movie
www.huzaifairfan.com
uncle.hyo.dev
student.ictkathurusingha.com
willu.idemo.app
jammuala.com
chit-fire.karthikkondri.com
link.keylifts.com
waitlistadmin.lingocoin.io
cdn-staging.lr-intake.com
marketplace-staging.luxify.com
sandbox.lynks.com
www.manhajj.com
live.marcosraudkett.com
mariiagregson.com
business.marsneo.com
dashboard.meet-johann.at
www.menteaberta.com.br
dev.monkeytype.com
dlsia.myassociation.app
admin.myphoto.com
tv.myphoto.com
dev.mziya.net
dl.app.natix.network
gatekeeper.nickradford.dev
dashboard.notyphi.com
nowims.com
www.obythree.com
oxyairmask.com
palminnmotelrosemead.com
payment.payrupia.com
phantuanvi.com
lightmysenses.piticommerce.com
polomarhealth.com
api.promoquo.com
www.pushakruna.com
bdfdesigner.regis-co.com
robinlepoutre.com
rodeoflo.com
www.ryanbrewer.dev
widget-staging.scorethebusiness.com
shanzid.com
shikhaayur.com
snapchat-clone.shiva-m.com
drops.blocks.simbachain.com
beta.sliptap.com
snehilsaluja.com
sunburydanceacademy.com
audio.suncollege.uk
surebro.com
taptechie.com
tavlabeni.com
www.taxihallecklimousine.be
teamdevproj.com
the-translit.com
mocksocial.thekima.com
theonlyone.ro
auth.turnonline.biz
twsportslottery.com
www.twsportslottery.com
unikhire.in
www.visionoid.com
staging-m.w50.com
weartogo.eu
xsync.network
Other domains in certificate