Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=815032.queenb.org.il
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 06, 2025
Valid Until
March 06, 2026
53 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CA:EE:2D:4C:F2:A2:BE:B5:11:31:53:DB:FA:41:F4:DA:E9:42:F3:C7:59:D3:6F:7E:FC:01:B8:2C:C5:B7:D6:C0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
solva.ar
nap.0xlabs.me
a2m-vision.com
addglamour.ca
short.arab48.com
www.asbsportsinc.com
test.topdesk.avisi-apps.com
www.ayushsitar.com
www.benger.biz
palermofc.deeplinks.bfansports.com
www.bigtimewallet.com
bloggies.com
testownfcm.bonrix.in
app.bookfren.com
www.bowandbeautiful.com
www.brookehowseestate.com
www.buildandbrew.online
burgosweb.net
bytoservis.eu
charliematina.com
donations.chefugee.org
admin.cnypassport.com
coimpul.com
www.colondev.com
store-admin.cutaway.com.tw
contentvoila.com
conversi.cloud
assets.cornwall-aonb.gov.uk
www.cristianramos.com
cristiansarghe.com
daytradejournal.com
dekarbonizaceceska.cz
smo.doikougei.com
dolguin.info
dragonereum.io
www.drink-happy.com
dskdao.xyz
www.eazycash.id
lm.edcliente.com.br
elitepersonaltrainersnyc.com
banner.fcsolucoesmodulares.com.br
rv-widget.fix4.com
caarea-dev.flitter.fr
predev-dashboard.futuralabs.rocks
stage.futuri.education
presence.app.getassist.co
www.getparkingfinder.com
gjallarhorn.news
expo.globalbuyersellermeet.com
gregweisbrod.com
heartcryelementary.com
herrajesposadas.com.ar
www.developers.iarahealth.com
www.irrly.com
coccos.jingjietan.com
www.karinaagaian.com
file.0plm.kro.kr
www.liesgame.com
lingwheel.com
materikab.com
qa.medpharmservices.com
writers.meetnewbooks.com
www.mipig.co.jp
evaluate.attractions.failte-ireland.mobilitymojo.com
msgdrops.com
mundokataros.com.ar
nexstepcollege.com
hub.nhayeu.com
815032.queenb.org.il
www.paolodipietropizzeria.it
parkingfinderapp.com
s.phnx.red
pollyon.com
app.qventana.com
tamuka.bookings.ratality.com
partenaires.reseau-sphere.com
robert-roehlinger.com
www.terezija.rocola.es
www.rosmarinengineering.com
sageye.io
www.seralfa.com.co
www.servergazivet.com
shamrockhomecare.com
sobrinostudios.com
www.sodalive.me
www.songshield.com
www.srirastusubhamastuevents.in
stephbrown.co
tampahouse4sale.com
finsuite.techforb.com
invite-staging.therecspot.com
mint.thesymms.com
www.ticketsparaestacionamientos.com
ultrababy.io
share.unifilm.de
www.vilannail.com
villa-nocturno.com
www.woningwaardekaart.nl
camp.yksw.org
yyconstructions.com.au
Other domains in certificate