Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=admin.collegiatex.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 29, 2025
Valid Until
March 29, 2026
69 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EB:D6:C3:FC:93:25:A4:7D:30:9E:74:11:3D:4A:D4:52:95:72:C3:33:21:33:44:D1:A4:E8:88:1C:FA:83:57:1D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
sharmainescakes.com
www.454motors.com.br
a-combinator.com
crm.additive-apps.eu
ai-bms.net
airfly.buzz
www.airfly.buzz
www.aktechnologies.in
app.aluguelanualflorianopolis.com.br
www.antonyhr.net
admin.carlos.anyware.software
grayhawk.arrowhealth.io
www.beginiaja.com
blog.bitto.jp
tgbot.bogged.finance
www.bypkle.com
dirlink.castpro.live
qa-v3.cavs.app
chesteritsolutions.com
www.cisibero.mx
www.clarx.com.au
clubinone.ch
codecollab.co.in
finaccess-staging.grobox.co.ke
admin.collegiatex.com
conx.es
cpas.ai
www.criteriumasesoriaslegales.com
auth.dogfood.cyberhaven.io
dartastic.io
www.dartsters.com
puzzles.hirata.dev.br
emircihangir.com
empotechlabs.com
admin.englishjanala.com
estudiogonzalezfabrizio.com
everbrosgames.com
finpic.com
florish.app
leadin-dev.gfn.de
vdilinks-qa.gnp.com.mx
www.hearme.tech
www.hetvertrouwdethuis.nl
sistema.homedetailecuador.com
ibstudyhub.net
icaroassis.dev
devnote.iggkenya.com
www.internationalveterinaryhealth.org
firebase.johanneskluge.de
jwashopfitting.co.uk
app.preprod.kjenndinkunde.no
www.konkankayaks.com
leapa.app
www.lmodonto.com
ultima.logical.health
chat.macky.in
madillume.site
www.markslawnservices.com
www.medisec.io
www.megastatekeralalottery.in
mentakademi.com
www.merasamaj.app
njgyp.org
nlalarm.app
dev.oto-media.com
perceptron.solutions
three-bank.pettiboy.com
phipeeps.com
picknote.co
ops.prottoyee.com
purestock.in
www.resonheart.org
app1.rhinontech.com
www.s7solucoes.com
sagos.info
scholarlabs.in
securethebag.app
www.skylled.dev
beta5.smilzz.com
www.spanalyze.com
cvfirebirdsshuffle.sqwadhq.com
input.stg.sumai-entry.app
staging-system.t-order.jp
inassets.terracat.co.nz
portal.textifyi.com
mcts.tixora.com
www.tkvelmos.ru
www.topibrotech.com
trvia.co
app.unifoodi.com
atlas.utah.gov
jobdesc.utah.gov
mdrop.dev.utah.gov
weedmusic.io
wrosswhite.ca
xclusivecarsbasingstokeltd.co.uk
xcolonstech.com
soupresenca.xptoconsig.com.br
yentla.com
zubairghori.com
Other domains in certificate