Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=berachajewellers.in
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 10, 2025
Valid Until
March 10, 2026
50 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
60:4D:C6:B8:C6:5C:C2:5C:18:E2:C6:82:A0:61:86:28:A9:70:0E:DB:8F:66:26:01:EE:00:6B:1A:E6:D2:47:57
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
summitloop.net
a.4kweeks.com
aarifcarpenteria.it
firebase.aaronchen.org
aesthetika.app
www.allesopzeggen.nl
blog.anclement.com
www.multibridge.angeldao.org
arcistudio.com
arjansuri.com
av2s.co
axelmry.com
www.azaniadriving.co.za
banda-ferdamana.si
beta.organisations.bash.social
berachajewellers.in
cbdata-test-backoffice.cbdata.cz
www.codeabsolute.in
www.dariakropacheva.com
sakurai.datateam.one
dev.dearfuture.io
deltacs.co.uk
www.digitalsocialweb.co.uk
dev.districtapps.com
dojodb.com
drjenafernandez.com
drwoo.org
indyrepnews.enotice.io
timetable-admin.entur.org
fci.jp
footsider.app
for-the-people.ca
dashboard.futuralabs.rocks
satzwuerfel.gabriels.io
gdlestore.com
staging.getladda.com
www.getyourspec.com
geurmelder.nl
globalleasinggroup.com
panel.gorent.pe
gotshift.io
gscribe.com
link.hexology.dev
hivemint.xyz
www.idanschiller.com
ija.co.uk
secure.iskconsolapur.org
jupyterwave.com
www.dev.your.karma.life
keeps.sport
khmenu.me
koloa.app
gift.labrador.ai
gamepad-latency.lambdasoup.com
duomdev.londonhydro.com
mannconstructionservices.co.uk
eventinfo.maprun.net
www.martux.cl
mass-dev.com
www.mavka.org
mayordiesel.com
app.media-literacy.jp
mehdiparyavi.com
www.melanatedhealthcare.app
metaphor.education
mmet.in
www.monomersoftware.com
s-webapp.monsuivilogement.fr
my-exams.in
network-design.com.mx
link-ntw.nibo.com.br
play.novious.nl
dev.onshop.lk
seats.sx.opentix.life
osmo.mx
phlotilla.com
premiumleaf.com
processmind.xyz
ptiqa2.pti.health
rachelplante.com
ranweli.com
www.renaultcentral.in
www.ristorantepietra.it
rosstechsolutions.net
www.samiraappana.fi
stagingmediatrack.service-unicepta.de
www.simplereverse.ca
mobi.sogil.com.br
voiptelecom.speakylink.com
valentines.speirs.io
swifthood.cz
uiuxtek.in
playground-data.upflowy.com
dreamland.vdimsa.com
vote4india.org
beta.wandb.ai
admin.plv.wowdesk.jp
twojacks.writerduet.studio
www.yourbloomingbuds.com
game.zodt.net
Other domains in certificate