77/100 SECURITY SCORE

Certificate Information

Subject
CN=onemetro.dune.it
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 01, 2025
Valid Until
December 30, 2025 47 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C4:9E:79:4D:5A:AB:18:06:EC:14:77:93:A5:E8:BD:10:33:76:1E:29:9E:A1:EC:7D:2D:FB:54:CF:0C:6B:60:C2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
vcrccontabilidade.com.br

Other domains in certificate

www.2g.no
3xerries.tech
arc-pricing-uat.5inline.io
www.aimhub.org
www.andreytreyt.com
admin.appjusto.com.br
grupomarisol.appshare.com.br
restaurant.appvelada.com
tanita.barin.app
bblockstudios.com
beautyjobs.uk
brijwasiinstitute.com
www.cadearcher.com
www.canadiansoccerplayers.com
www.casahorizon.com
shopping.christianaquino.net
tinyunit.co.th
coloring.ly
denverheralddispatch.column.us
crein.net
onemetro.dune.it
app.efactori.be
www.everette.io
fantasyfootballmanager.app
wellbeing.fhinck.com
auer-dult.fischer-vroni.de
sharing.fitbeat.com
www.flaggs.co
flowsportclub.com.br
subtract.fnflk.com
gdj5.foodle.su
forfettariotasse.it
futuresoftware.io
gadverdam.me
i.gbg-go.com test.gbg-go.com
dynamiclinks.getparasol.com
smi.hertleinj.site
hollowayli.com
hypelotto.com
ikdev.it
www.intelligence4people.com
join.333.eco
www.jommakaneatery.com
www.kayciparcells.com
kevinlysocial.com
www.kidsupsoroban.vn
rominagamarra.kiwikode.io
www.krishiagent.com
app.kunnonsalkku.com
womenforsafety.lapieza.io
app.linkman.co
smc-temp.littlesparkiot.com
masterclassai.site
api.mobilab.ai app-staging.mobilab.ai app.mobilab.ai bizops-staging.mobilab.ai bizops.mobilab.ai lab.mobilab.ai prod.mobilab.ai research-staging.mobilab.ai
www.moredolab.com
myhr.tg
myrabia.com
swu.myratune.com
noordelijkehorizon.nl
auth.ogam.ai
oprograma.com
otira-sulotions.com
static.planmylife.app
admapp.rendilitros.com
www.renzocallachavez.xyz
attendance-calculator.rohitjoshi.in
ruralvisionary.org
www.sa-haar-ra.at
seurasas.it
www.sheepdogandwolf.com
shiftjobs.uk
simoneferreiraimoveis.com.br
simpleclub.de
auth.smotrowrelated.com
somosmario.org
www.data.spottimetta.fi
starwinafrica.com
stianantonsen.com
demo.live.stratodigital.io
thechildhut.com
www.thedaysofraj.uk
tivra.io
tokenpow.com
unityexperts.com
app.vieon.vn
wbvsupplies.com
wilkie.dev
www.wooltarisoft.com
yellowspyglass.com
solvrzinc.yugthapar.com
link.zam.io