91/100 SECURITY SCORE

Certificate Information

Subject
CN=support.lawful.legal
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 08, 2026
Valid Until
April 08, 2026 73 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8A:EC:98:61:27:2C:6B:1A:EE:82:F2:28:4F:1A:BD:BD:69:DA:B9:8B:71:3F:A4:D0:F1:E5:AC:93:4E:65:F7:B2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=63072000;includeSubDomains
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Present
accelerometer=(), ambient-light-sensor=(), bluetooth=(), compute-pressure=(), document-domain=(), encrypted-media=(), gamepad=(), gyroscope=(), hid=(), magnetometer=(), midi=(), screen-wake-lock=(), serial=(), speaker-selection=(), usb=(), xr-spatial-tracking=()
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking

CAA Records (Certificate Authority Authorization)

CAA Records
Configured (Restricts certificate issuance)
Current Issuer
Authorized (Matches CAA policy)
Recommendations
  • Consider using critical flag (flags=128) for stricter CAA enforcement
  • You have authorized 4 CAs - consider limiting to only the CAs you actively use
  • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
  • Consider adding 'issuewild' records to control wildcard certificate issuance

Subject Alternative Names

89 domains
fuelsupport.avalan.com rma.avalan.com support.avalan.com

Other domains in certificate

servicedesk.accessoshoware.mx
support.activefleet.com.au
ketzalmarketing.advancio.com
suporte.allphasystems.com
support.alohaaba.com
support.arbor.tools
support.atptree.com
support.autmow.com
biz-support.avatarin.com
support.avianis.com
support.baysidetechnology.com.au
solutions.benavise.com
support.ceo.do
help.charterace.org
boms.helpdesk.cipi.net
support.cleaningresource.com
netevia.clearsolutionsip.com
www.primarchomes.co.in
help.coachusa.com
ayuda.casham.com.do
131.circlegroup.com.my p40.circlegroup.com.my
support.conquestis.net
support.cp-commerce.com
custservetest.credibly.com facilitiestest.credibly.com
support.datahash.com
help.delynke.com
support.dexpress.com
support.diamondstandard.co
support.digitalshiftiq.com
engineering.dmflighting.com
help.enstack.com
support.epescode.com
support.eznextgen.com
service.fibertel.ca
helpdesk.firmwerx.com
support.fsdae.com
eppf.fuseit.co.za
support.gosmp.co
trafico.iflow21.com
support.imc-llc.com
helpdesk.incustech.co.uk
barco.inflowtechnologies.in dell.inflowtechnologies.in netskope.inflowtechnologies.in onelogin.inflowtechnologies.in rsa.inflowtechnologies.in thales.inflowtechnologies.in
desk.ironresponse.com
helpdesk.its4b.com.au
ei.jgbliteng.com
support.lawful.legal
soporte.leadu.mx
support.mechtechsolutions.net
support.myprepcourse.com
admincenter.accesspoint.net.ar
itsupport.nexus-sr.com
desk.nimbis.com
support.olympusconsulting.com
support.openvpms.com
helpdesk.pahamify.com
support.palcare.com
help.popecountymn.gov
support.primeusedparts.com
support.quattrocom.mx
help.realit.nyc
zoho.rfgadvisory.com
rfsit.rfsmart.com
support.romaresources.com
support.securewaytech.com
support.sellersshield.com
support.sltrust.co.za
support.sophya.ai
blog.steeplemate.com
support.stillgood.co.za
desk.surphaces.com
support.techexdigitals.com
support.tightropeinteractive.com
helpdesk.titanftp.com
mss.tnctrade.ae support.tnctrade.ae
kb.touch2success.com
helpdesk.tradinos.com
support.wholesomeyum.com
payments.zylkerinc.com