Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=beta.quash.ai
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 24, 2025
Valid Until
March 24, 2026
89 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3D:B1:63:DB:CC:EF:EE:AD:5A:82:0E:2B:43:B6:9D:CA:BA:FA:F7:C0:50:32:B6:5A:E6:21:91:6A:72:1D:FB:12
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
tlthmp.com
www.3langschool.com
pwa.law.7yhps.com
www.aayushsoft.com
bytsai.adtheophanix.com
akmanager.in
www.andreasbagias.com
www.androidmanifester.com
anisbakeryandhomefoods.com
antsegseguros.com.br
bms.anvileight.com
apparentpower.net
www.apparentpower.net
map70.aroundit.net
assoc-retired-ironworkers.org
banklogshop.mp
beansapptest.com
www.billable.pro
birthdaycountdown.app
amag.console.bringo.me
www.burryport.uk
qe.astra.choozle.com
cjcmch.org
kawari-uat.iamconsulting.co.th
yesimozgen.com.tr
creatiweb.site
desordre.in
dotek-krasy.cz
www.dytmustafayontem.com
elitechirotech.com
eloraearth.com
www.embrodia.com
www.euclidextruded.com
findoc.es
finmitr.com
www.formully.com
uat.fxhub.co.za
www.gmist-global.com
reports-winery.grapeweb.com.au
gyfdrop.com
www.hexiradigital.com
hp-werner.de
dev.hububz.com
staging.hvaskjerkalender.no
hyde-livegoods-store.com
tesseract-staging.inamo.in
jeg.li
www.kaanyazicioglu.com
www.kaninklubb.no
kemph.com
www.kemph.com
en.koenig-ludwig-stuben.net
appadmin.kouyahikosaka.com
strava.kpots.com
uniqueleru.kro.kr
lovedeliveredcards.com
prom.lskel.com
www.ltcwages.com
mangoinabox.be
tls.mcmhq.com
microactiveinc.com
avancar.midiacode.app
mindsonline.com.br
moca.cash
mykindmind.app
nahuitech.com
naturalgas.fyi
tarifario.nitesincoming.com
www.noelwhitaker.com
orderofthekla.org
www.orderofthekla.org
parallelventures.eu
www.peacejam.org
peaceofmind.coach
peomodel.com
beta.quash.ai
ran-studios.com
rasibzaman.com
revolutiondancewearhire.co.uk
accounts.roadbotics.com
seohashtagger.com
bookremeet-canary.spaceeight.net
prices.svydis.com
bodaciviljazminyluis.swanmoments.net
tau.software
1214hotline-ar.techforcelb.com
sandbox.console.tilt.rest
www.toworksmile.com
teo.tubot.es
boe.hamamatsu.links.org.services.int.unpaidworks.com
uzayakademi.org
www.vaishnavipowers.com
www.vcu.network
mobile.haven.viancorp.net
vyabyl.com
wealtharc.in
worldhealthlab.org
store.yona.app
www.ytolun.com
zz.zulunity.cloud
Other domains in certificate