76/100 SECURITY SCORE

Certificate Information

Subject
CN=oxido-iq.info
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 04, 2026
Valid Until
September 02, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E4:92:B4:0E:2B:52:50:DB:3B:3F:B3:32:4A:0A:EC:B3:AA:EE:7B:9F:D4:36:01:78:9C:D0:B0:10:94:96:DC:7D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
buber.school *.buber.school *.api.buber.school *.app.buber.school *.backup.buber.school *.dashboard.buber.school *.dev.buber.school *.gitlab.buber.school *.ivjqznsb.buber.school *.lgazwpfd.buber.school *.mail.buber.school *.mailer.buber.school *.marketing.buber.school *.new.buber.school *.qa.buber.school *.secure.buber.school *.staging.buber.school *.stg.buber.school *.uat.buber.school *.v1.buber.school *.v2.buber.school *.www.buber.school *.yrkvddev.buber.school

Other domains in certificate

*.838c1b31-874a-470a-9b02-d09fd2bbefdd.gizmojigs.com *.admin.gizmojigs.com *.api.gizmojigs.com *.assets.gizmojigs.com *.backup.gizmojigs.com *.dashboard.gizmojigs.com *.demo.gizmojigs.com *.dev.gizmojigs.com gizmojigs.com *.gizmojigs.com *.mail.gizmojigs.com *.mailer.gizmojigs.com *.qa.gizmojigs.com *.remote.gizmojigs.com *.secure.gizmojigs.com *.staging.gizmojigs.com *.stg.gizmojigs.com *.uat.gizmojigs.com *.v1.gizmojigs.com *.v2.gizmojigs.com *.vpn.gizmojigs.com *.web.gizmojigs.com *.ziejftkv.gizmojigs.com
monerafundsforbiz.co *.monerafundsforbiz.co
*.admin.ormas62.org *.api.ormas62.org *.app.ormas62.org *.assets.ormas62.org *.backup.ormas62.org *.bnamrdashboard.ormas62.org *.cxtmjadmin.ormas62.org *.dashboard.ormas62.org *.demo.ormas62.org *.dev.ormas62.org *.docs.ormas62.org *.external.ormas62.org *.hdplddev.ormas62.org *.mail.ormas62.org *.mailer.ormas62.org *.marketing.ormas62.org *.my.ormas62.org ormas62.org *.ormas62.org *.portal.ormas62.org *.public.ormas62.org *.qa.ormas62.org *.sbwridocs.ormas62.org *.secure.ormas62.org *.sharepoint.ormas62.org *.staging.ormas62.org *.stg.ormas62.org *.test.ormas62.org *.uat.ormas62.org *.v1.ormas62.org *.v2.ormas62.org *.web.ormas62.org *.wjyxclug.ormas62.org *.womjedev.ormas62.org
*.a.oxido-iq.info *.api.oxido-iq.info *.app.oxido-iq.info *.dev.oxido-iq.info oxido-iq.info *.oxido-iq.info *.staging.oxido-iq.info