77/100 SECURITY SCORE

Certificate Information

Subject
CN=iskial.pl
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
April 21, 2026
Valid Until
July 20, 2026 72 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C7:D3:3E:AF:2D:13:C5:FF:9A:8A:BF:E9:49:81:49:3A:4B:4B:DB:3D:C9:80:55:92:BA:BC:1A:EC:5D:D1:EA:45
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
swiftresolve.digital

Other domains in certificate

sp.claimconnect.4-sure.net
console.actinius.io
r.apap.pl
romanceai.applora.io
app.arbortrak.com
onsite.blastitallchicago.com
bookilydz.com
ccl.boothpilot.com
forever-insurer.cardiflab.com
carloscastillo.online
wingtai-landmark-east.carnotinnovations.com
www.cool-story-project.com
darrylday.ca
admin.dasistan.com
deltaswift.buzz www.deltaswift.buzz
dersasistan.online
descriptgen.com
customer.ovn.devserver.cc
staging-labelling.dinohub.io
focus.drtis.com.br
dynamosalliance.org
easygolf.net
www.ekoputos.lt
vamap.evidencebasedassociates.com
extratransferjeddah.work
firebase.ezview.kr
admin.fair-warning.com
shopify-admin.falconconsulting.fr
sandbox3-api-docs.flexm.com
table.folkin.io
tick.freelivenet.com
geovanateles.com.br
gerits.dev
goldmarvel.net
virtual.grandcasinobaden.ch
grepin.in
gsm.dev.br
www.hatchbetter.com
ichoo.sr
hims.ida-org.com
www.indice51.com
link.insunet.co.kr
interviewquestionsgpt.com
irrelevantindustries.de
iskial.pl
reddit.joshuabennett.dev
staging-promoter.kaboodle.co.uk
kingswaybuilders.ca
14-160.koneta.click
formacion.rugbymexico.lernit.app
www.lingtang.rest
lionfoundry.com
mark-it.ai.kr
metmede.lt
milkywaystudio.ca
omnigon.com.ua
onebubble.ai
www.onshapetutorial.com
livestream.oomphwellness.org
eraser-dev.pencilspaces.com
www.pinkdhaga.com
www.plasproject.org
privietweb.com
protocolnine.com
stagingftcchatengine.proxtera.app
rakutenadvertising.io
www.rektproof.com
connect-ng-carrier-dashboard.rxoconnectdemo.rxo.com
saturdaysundayfilms.com
screening-test.scaleupconsulting.com.au
auth.scout.parts
myfarm.seetree.ai
shahinhassan.com
shreddit.io
sns-on.net
www.solplay.de
www.splashysprint.com
invite.sportup.io
www.sportyapp.com
sprintnex.us
studpi.com
superverse.page
tangogameunlimited.com www.tangogameunlimited.com
techaeon.org
www.telepuja.com
kokino.thediners.in
www.tngroupsoftmsk.com
tristanjin.com
tykari.com
tylercoopernd.com
tzonneke.be
verdantlabworks.com
www.victorfarrell.com
vitaia.ca
voxconnect.app
wadirealtors.com
admin.wrisgh.com