Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=fe-metallbau.gocad.de
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 18, 2025
Valid Until
March 18, 2026
83 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D7:0A:A3:7B:13:5B:20:CE:D7:26:00:08:44:C7:90:26:83:30:99:31:22:CB:08:7C:24:69:BD:72:22:F3:F3:20
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
techhubapp.hypernova-prime.in
optimize.7sindhu.com
convergence.vnrvjiet.ac.in
adsimplr.com
v7hazirsite.agtdijital.com
www.amafitness.nl
apexlegalhub.com
www.apicoach.io
www.appeletrico.com.br
restorative.aspireinclusion.app
asquareassociate.com
paris92.deeplinks.bfansports.com
biz520.com
www.biz520.com
bodabeatrizydavid.info
bier.briefdocs.org
web.builderbookkeep.com
chatandgoapp.com
androidmani.chozhanaaduapps.in
www.partsshop.chrislauer.net
dashboard.t-ride.co.tz
alpacaapps.com.ua
comeontime.com
www.designhive-group.com
dhanifinancesloan.com
donkey-milk.eu
dpmc-llc.agency
provider.eassylife.in
x4ijavj78gev3edm.easyapp.co
x5vpjz.easyapp.co
x6syvxffkxp2g.easyapp.co
xowi37.easyapp.co
edonico.com
gtu.etraineducation.com
www.evernest.de
www.explorza.com
firebase.asia
clientes.fixbit.mx
www.flashcardsaiapp.com
genpaps.com
coffee.getorda.com
globalrv.in
fe-metallbau.gocad.de
admin.havenforkids.fun
honeyrisweet.com
duoc-dz.id.vn
nxtno1.id.vn
uat.in-option.com
ingservices.org
grams.inweon.com
www.karobarlauncher.com
bestellen.kekosfood-kleve.de
kivra.services
www.knockstoppers.com
lewatsini.chat
bscsharktank.mavrck.co
athena.meuportfol.io
attach-x.mikmak.tv
www.mlowe.net
mtjenterprises.org
myolist.com
auth.ride.mypeople.in
nandarodriguesoficial.com.br
www.nexaglobal.capital
flip7.overthe.cloud
link.papertale.tech
patternpulsetrading.com
wohnungssuche.pechi.at
penguintots.com
www.penguintots.com
bestellen.pizzagrottino.de
sipen.pleasecuddle.me
xterm256.pplan.top
www.qiangse.autos
console.qrfresh.com
randommallu.in
www.rihshengtech.com
rivonidhi.com
m-dev.rydcloud.de
sentinelsearch.ai
shanedancy.com
sukoda.ee
www.sukoda.ee
studentqa.tassorbit.com.au
www.theartofbraces.com
thetooth.co
www.thetooth.co
toitronglan.club
www.transformationworks.com.au
vaconsulting.services
venturoo.live
genesis-gallery.vibefoundry.studio
www.wakhti.org
wearallblack.com
msfsportofolio.web.id
winmetsencor.nl
www.adexports.work.gd
www.yieldpoint.ai
admin.yogkshemladnun.com
subadmin.yogkshemladnun.com
Other domains in certificate