76/100 SECURITY SCORE

Certificate Information

Subject
CN=thorwood.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 13, 2026
Valid Until
May 14, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
21:7F:81:A8:14:6F:7D:BF:2D:05:1C:21:5B:D5:6B:FE:9A:7B:51:80:48:56:6C:9E:7C:AF:37:47:EB:BE:75:3F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
norlander.com *.norlander.com *.admin.norlander.com *.api.norlander.com *.autodiscover.norlander.com *.backup.norlander.com *.cisco.norlander.com *.ciscovpn.norlander.com *.connect.norlander.com *.cpcontacts.norlander.com *.dev.norlander.com *.drvpn.norlander.com *.exmb1.norlander.com *.ftp.norlander.com *.imap.norlander.com *.m.norlander.com *.mail5.norlander.com *.mailgate.norlander.com *.mailgw.norlander.com *.openpgpkey.norlander.com *.ra.norlander.com *.ravpn.norlander.com *.relay.norlander.com *.remote.norlander.com *.secure2.norlander.com *.sslvpn.norlander.com *.test.norlander.com *.webmail2.norlander.com

Other domains in certificate

aqdx9.com *.aqdx9.com *.bvip.aqdx9.com *.comvip.aqdx9.com *.vip.aqdx9.com *.wildcard.aqdx9.com
audienatom.com *.audienatom.com *.wildcard.audienatom.com *.ww25.audienatom.com
dwok7880e4r45of4kd5csyd9in2gsp1.top *.dwok7880e4r45of4kd5csyd9in2gsp1.top *.ipvhhgzu3a.dwok7880e4r45of4kd5csyd9in2gsp1.top *.sitemap.dwok7880e4r45of4kd5csyd9in2gsp1.top
*.api.espresso.baby *.dev.espresso.baby espresso.baby *.espresso.baby
jrojas.com *.jrojas.com *.m.jrojas.com
*.api.magicalweddingsexperience.beauty magicalweddingsexperience.beauty *.magicalweddingsexperience.beauty
*.jaipur.pmssjaipur.com pmssjaipur.com *.pmssjaipur.com
*.admin.preciousunionservices.beauty *.api.preciousunionservices.beauty preciousunionservices.beauty *.preciousunionservices.beauty *.shop.preciousunionservices.beauty *.store.preciousunionservices.beauty
*.api.primecartop.com *.portal.primecartop.com primecartop.com *.primecartop.com
*.ae2b0604-8e6d-47c1-8af8-35047606f8c8.rayuko.com *.mail.rayuko.com rayuko.com *.rayuko.com
*.hostmaster.surgery.tips surgery.tips *.surgery.tips *.ww17.surgery.tips
*.m.thefortworthdaily.com thefortworthdaily.com *.thefortworthdaily.com *.vpn.thefortworthdaily.com
*.m.thorwood.com thorwood.com *.thorwood.com
*.m.vuorela.com *.mvr.vuorela.com *.ra.vuorela.com *.ssl.vuorela.com vuorela.com *.vuorela.com *.webmail.vuorela.com
*.wildcard.xn--vjq503a.tv xn--vjq503a.tv *.xn--vjq503a.tv