Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.lotony.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 05, 2025
Valid Until
January 04, 2026
49 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A3:78:D2:88:E3:92:29:6C:C3:0B:39:55:42:45:EE:E7:37:E5:24:C1:33:CA:E8:1F:73:FF:70:65:B7:5E:18:F4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
system.a1groupservices.com.au
27thnight.com
staging.sms.gtc.ac.nz
acruxphoto.com
api.aeroster.com
staging.alphasmithy.com
australia.amnotify.com
andrewcwheeler.com
nudges.apxor.com
www.ashguy.com
cv.atil.io
www.auggie.app
projects.autolight.io
raa.azgfd.com
www.barmapper.co.uk
gem-russ-getmarried.bitmoremedia.com
app.boards.com
experience.bournemouth.ac.uk
wod.boxscorefitness.com
www.charcoalsystem.com.br
api.cofounderai.com
apps.corsarus.com
portal.crackersicon.com
cultivatemakers.org
cyberworks.com.au
orders.ddmotorsystems.com
www.doai.in
dokozel.de
www.driveelink.com
ec-digger.com
mvt.app.electroluxlife.electroluxmobile.com
elmshore.com
farmerjohnsonoffroad.com
www.felixriedel.me
firstvillageva.com
www.flightcontrol.online
get-staging.fresbopixel.com
www.fringers.pl
app.gamifier.co
www.service.gigtag.jp
goldennumbers.com
extension.hamptoncollege.cl
hutapp.handong.app
harmonyplume.fr
auth.dev.hiemile.com
stage.ibegoo.com
www.amanmaharjan.info.np
bud644.itesa.ar
app.typetypego.jakesmd.com
karinasands.com
www.kieranhodge.co.uk
www.kopal.at
lanzon.co.uk
www.lotony.com
mahalaxmiicecreams.in
www.mathring.org
measure.team
www.mission45.be
cashback.mixerbox.com
beta-docs.modalai.com
movingtarget.studio
www.mexico.myrentokil.com
app.mysuitefam.com
niladriraychaudhuri.com
www.nutilt.com
homework.nzacademy.co.nz
obrimo.com
www.okotoki.com
auth-test.oresundsbron.com
www.otobesa.com
phq.nz
app.pixelmob.co
platfrm.us
help.qrtrac.com
api.roboflow.ai
www.rolsma.com
www.saintmichaelschoolhn.com
my.sb-fm.co.uk
timer.schmorian.de
bch.strongline.smplabs.com
somos-grandes.work
studdy.app
kitchen.supperhero.io
camaramelarawedding.swanmoments.com
systemslab.dk
admin.tajmahalde.com
www.talentics.mx
tashidgyeltshen.com
teakstweaks.com
timefiddle.com
app.sandbox.tracis.io
devapp.trydownstream.com
tsurugakj.com
im.uno.kim
webhost.com.au
staging-admin.whatsauto.com.br
pte.whdreams.com
wictrans.wic.ci
www.yeniev.net
link-pre.yqb.jp
Other domains in certificate