77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.craigspace.eu
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 19, 2025
Valid Until
March 19, 2026 87 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
03:E3:DD:EF:FD:10:AD:3E:88:EE:A3:13:B1:E4:CE:6F:45:2B:B0:85:46:40:19:AF:AF:D3:43:D2:46:79:35:00
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
stapf.bacotech.com

Other domains in certificate

www.365things.co.jp
cwit-beta.acuizen.com
adamrosellc.com
alexbogovich.com
s.aloha-group.jp
games.asitri.com
www.avtransportesbr.com
bakarybarro.com
banklogs.mp
barkatgreens.com
hack.bayes.org
bedsoflove.com
www.betaflops.com
test.binaryinfura.com
bobcampbellpainting.com
www.busico.net
play.byallrights.org
carselandrestaurant.com
cliftleighcarwash.com.au
www.chatwithme.co.in
www.codethatdown.com
confessum.com
www.confluencelab.org
www.consciousyogamar.com
www.coolmoves.fun
correosvisit.es
www.craigspace.eu
curryavenue.com
derekhowles.com
df-it.services
www.dincfopartner.dk
professeurs.diploma-sante.fr
dnafriend.com
erp.ekmastudio.ca
www.elitemapacademy.com
enlightbusinesssolutions.com
enzzy.com
usbancorpcenter.equiem.mobi
felixguenthner.com
getapp.flyfin.tax
fdeli-app.frt.vn
artist.furry-online.com
gamingcurves.com
www.hanzi-cards.com
app.hardcapp.com
heatingarash.com
history.photo
www.iamtom.online
iculearning.com
inventoryflow.in
josephwalewski.com
test3.kiki.finance
kuryelerbirligi.com
tkc.lfv.jp
dashboard.lifebase.solutions
app.dev.login.earth
www.logopedabialystok.pl
malappuramchurch.com
mdaem.com
moart.club
www.mptindex.com
multimax.store
multiverse-marketplace.com
www.mutti.catering
www.nilauto.fr
d.noxchat.in
nthuawb.tw
www.pariworld.org
www.piggibanks.com
pimchile.com
productscout.pro
qbt.finance
quickbuildnew.world
arthur.recursyve.dev
www.rekoapps.com
www.reliance.lk
reptop.shop
admin.repzone.mx
rgbx.io
connect-lite.scoutout.co
my.securemydesktop.com
message.sherwoodnissan.ca
shpdental.com
piknik.sifrovacky.cz
www.snapit.ph
soundlight.io
hantsch.speakylink.com
www.staticregainband.com
studiopixl.com
qr.styreportalen.no
surimico.com
images.tempestapps.io
www.thebonningtonbeast.com
luft.thediners.in
www.travelpremium.com.pe
usefreelanceiq.com
www.valleywork.ca
vieirarocha.com.br
zupra.property