Open Cached · just now
75/100 SECURITY SCORE

Certificate Information

Subject
CN=spec-cnc.pl
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 28, 2025
Valid Until
January 26, 2026 75 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1A:F5:70:27:B9:21:FC:B1:34:7C:D5:83:74:0C:93:5B:FD:9C:BF:16:91:21:DC:CD:C7:A9:08:9D:21:43:7B:0D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
vermillion.app

Other domains in certificate

dlg.12traits.com
2019.ngvikings.org
aahtienda.com
activecare.aeglepro.in
ajsmobilewrench.com
amardeepforging.com
antoreek.com
www.banditobee.com
bellezasmexico.com
chess.benjiwong.com
berimbaugamestudio.com.br
www.bluink.app
bydru.com
misayudas.cabildodelanzarote.com
www.climbingcommunity.co.uk
www.noorcomnetwork.co.ke
crispcity.com
staging.delvcareers.com www.delvcareers.com
feedback-2023.devduck.de
drbanna.com
kodigomusic.dummy.website
grid.ecomacy.com
chargepoint-simulator.electriphi.dev
lims.enkept.com
www.ericgar.com
8th.fcis2023.me
fiveminutecloud.com
staging.fleet.ph
focus-admin-staging.com
freelance-direct.app
g-tomic.com
link.beta.geovelo.fr
gutsyapps.com
happyhousekeepers.ca
www.hfccoin.org
dev.hsechoir.org
www.iaf-kampfkunst.de
inoprealty.ae
gh-de-ify.input4you.be
intimateconnect.com
www.izzistock.com
jbdcollege.com
admin.jumaentregas.com.br
juniorcircle.in www.juniorcircle.in
karenultimatedictionary.com
www.kochbibel.com
app.staging.lifeestateorganizer.com
www.lifeshow.app
foray.loadsure.net
lokobox.de
luminaapps.co
m3nu.me
digital-showroom.maje.com
dev.maskcount.com
mementr.com
meninasdoceiras.com
www.mergein.io
mesbro-welfare.mesbro.in
customer.metrodyeing.com
app.minigolfmadness.in
app.moveup.app
static.mpy.ro
mrch.at
naala.app
www.naeembux.com
www.normallyopen.com
okanpay.okan.jp
olewintechsolutions.com
kyprl.papageorgiouk.com
work.petchpatthana.com
phonebuddy.app
surewin.pslove.dev
servitout.recursyve.dev
checkin.revo-ehr.com
www.royaldestinationtnt.com
etch.roytown.net
sasolburgboulevard.co.za
app.sayedalialkamel.com
bromley.scouthub.app
app.shareyourbusiness.com
compras-sitionovo.silconp.com.br
spec-cnc.pl
tap.place
diy.telecrm.in
tempotify.app
www.tokachimusubi.com
tuft.tolobanj.org
transportedirecto.com
twinlots.com
www.ugmaxwin.org
www.uknow.global
miau.ursem.ca
valoremapp.com
mail.vimeet.app
new.viszya.com
postboard.waymondrang.com
zivosolutions.com