77/100 SECURITY SCORE

Certificate Information

Subject
CN=suji-seitai.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 12, 2025
Valid Until
January 10, 2026 33 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F6:3D:5F:76:97:28:F1:1A:92:59:33:C4:90:88:EF:A1:A1:E6:28:42:AE:DA:53:BC:A6:1E:CC:06:64:21:9F:FA
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
v2.joseph-san.com v5.joseph-san.com v6.joseph-san.com v7.joseph-san.com

Other domains in certificate

letizia.11yearsafter11.nl max.11yearsafter11.nl
22bate7.com
registration.4-sure.net
www.7mdigital.com
developer.adgenticplatform.com
chatbot.appypie.com
atharvawarke.com
admin-portal.bambumeta.software
www.barnettecpa.com
bigpiq.com
www.billexpense.com
billjohnson.me
bioherby.com www.bioherby.com
biopmconsulting.com
biopminc.com
birensuthar.com
www.bjcollins.tech
moksha.caarya.cloud
web.callassistantapp.com
carbacademy.com
www.careerlego.info
telemedlab.casemedservices.org
www.chroniker.co
auth.diarybunda.co.id
ocm.staging.admin.convercus.io
danieldemissie.com
ninja-smoothie.danielpayne.co.uk
portal.deepsentinel.com
reweigh-5.dev-ltl-xpo.com
devite.pl
test.dive.chat
dsstars.com.br
economia-real.com
examenvtcmadrid.com
a0g8.foodle.su
friendsofauburn.com
app.funfute.com.br
video.apps.gaiahsilver.it
getcouped.com
data.analytics.getrident.com
sales.gorout.com
groebert.org
www.halloweenjack.com
hpp.to
imbianchinoimola.it
www.imitox.com
prosa.improvequality.it
www.temich.in.ua
vks2.indiandevelopers.org
dev.speedlearn.isoglitch.net
knappekapoentjes.com
kpocho.cl
my.lazylawn.ca
learnbread.com
levelupdimona.com
www.linaresleon.com
promo.makamaka.by
apps.mandarin.sa
www.morreach.com
rocket.moss.land
www.museumrealm.com
teentoon.my.id
mobile.nicket.do
app.trial.sam.nimaru.jp
client.onlinetestyap.com
aac.optelgroup.com
cryptonium.originhorizon.com
verify.oxeye.ai
video-to-screenshots.peterbe.com
app.pinecovecamplife.com
pixelrelicgames.com
pixelversemuseum.com
www.plannable-notebook.com
www.poky.men
www.profalme.com
rapidsignupfl.com
benin.rc-materialculture.de
nextv.remotemonster.com
document.rinkt.com
dtxnft.riseaccel.com
royalleaps.com
www.ryantsangai.com
www.salwirak.pl
scottsizemore.com
www.sealinkinfosys.com
shogimetrading.com
kyoso-official-stg.sophia-s.co.jp
sportivecm.com
suji-seitai.com
www.swingjeans.it
uniqlu.syabinaap.site
www.tracker.pub
tu-map-drawer.online
payments.webcat.app