Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.tomassodigital.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 23, 2025
Valid Until
March 23, 2026
88 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FE:15:5F:8E:13:1E:08:B8:B9:AF:C5:AE:17:E6:1E:E8:06:82:8D:E3:C3:AD:A5:36:F4:A3:84:0F:31:29:A0:89
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
spindoctortennis.com
www.2nv2u.net
www.adshi5.com
go.ambrook.ag
www.appodiz.com
axieacademytracker.com
barcoder.tech
jeu.baristacafe.nc
gymnacode.blueur.com
prizecloset.brainsprays.com
callbuddy.ch
cardsplus.org
rqam-cbd.carnotinnovations.com
www.ceyaexport.com
www.chamaodelivery.com
moje.chytranemovitost.cz
www.clintonrivertraffic.com
www.codesur-solutions.com.ar
e3s.coloredpuppy.com
lovetechnigeria.com.ng
erasolutions.com.sa
store-service.daikin.com.vn
magic.comazon.dev
www.creativeseed.com
daraphillips.com
www.detyra.de
www.dianabraganca.com
dilhocam.com
www.doktor-tir.pl
www.dotaexp.com
www.equipogiochi.com
rtl.femoli.com
filipkowalski.com
join.flapcards.com
www.cc.frontfacer.com
www.fruehstuecksheld.com
partner.future.rent
firebase.gamerarena.com
genomestream.com
www.glur.ch
www.helpaddict.ru
iaccept.in
rajyotsava.ilikacloud.in
dev-stage.jcuapp.com
jimjonesallstars.com
johnson167swimmingpool.com
joshreed.dev
cloudfunctions.joymo.no
www.kalebmurphy.com
karwasara.com
kp.345.fi
ksslc.com
by.lajoscseppento.dev
lightofaya.com
www.locltour.com.au
mampf.luzzifus.de
memosis.sk
michichef.com
e.milva.dk
mypuzzlelibrary.com
mytradinglab.live
contact.nazarovgeo.com
www.nemesislabs.com
hc.neumobot.com
www.novimgames.com
test.oddmonitor.com
ordu.com.au
orinqo.co.za
paillardes.app
app.pauseable.com
www.penguni.no
periscolaire-chenoise-cucharmoy.fr
plannedadventurepro.com
www.polysquat.com
clients.prohr.solutions
www.projection-lab.com
purposeunpluggedlifecoaching.co.za
www.pyli.io
riverrockmedical.com
www.riverrockmedical.com
link.servicesmeubles.com
www.solutionselectrical.ca
enedis.speakylink.com
training.structube.com
mta-sts.tabl.page
pleppy.tarpo-hiraoka.com
www.teleflextraineesettlement.com
theupperbasement.com
www.thienky.com
bitcoinbounce.thndr.gg
www.timesync.io
www.tomassodigital.com
tunacancup.com
u-goservices.com
www.verrocchi.com
viadellazzurrabeb.it
walmartnhj.com
www.yarafoods.net
www.ydsmaster.com
zophiria.com
Other domains in certificate