76/100 SECURITY SCORE

Certificate Information

Subject
CN=dwgrp.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 21, 2026
Valid Until
July 20, 2026 76 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7B:90:52:0C:6F:CF:F6:9C:6D:31:9C:3B:6E:22:AE:16:01:6C:87:FB:F3:8A:E4:A1:3B:7E:D2:28:DB:64:93:C6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
dwgrp.com *.dwgrp.com *.api.dwgrp.com *.apps.dwgrp.com *.blog.dwgrp.com *.bmqqeapps.dwgrp.com *.cisco.dwgrp.com *.email.dwgrp.com *.exchange.dwgrp.com *.gestion.dwgrp.com *.imaps.dwgrp.com *.mail.dwgrp.com *.mobile.dwgrp.com *.nbjteautodiscover.dwgrp.com *.owa.dwgrp.com *.rd.dwgrp.com *.secureaccess.dwgrp.com *.shop.dwgrp.com *.sslvpn.dwgrp.com *.test.dwgrp.com *.vdi.dwgrp.com *.web.dwgrp.com *.webapps.dwgrp.com *.zmcaayjrjjcpcontacts.dwgrp.com

Other domains in certificate

*.10afd5a5-48e1-4cdd-b94b-ddb7a4b5610e.monkeybean.ca *.4824678a-d7f5-48be-a33f-31060001479e.monkeybean.ca *.access.monkeybean.ca *.activesync.monkeybean.ca *.admin.monkeybean.ca *.api.monkeybean.ca *.app1.monkeybean.ca *.app2.monkeybean.ca *.appliance.monkeybean.ca *.apps.monkeybean.ca *.apps1.monkeybean.ca *.asa.monkeybean.ca *.authenticate.monkeybean.ca *.azure1.monkeybean.ca *.bc301bfd-e006-4fd2-8f1e-4906d8c19fe0.monkeybean.ca *.checkpoint.monkeybean.ca *.cisco.monkeybean.ca *.ciscovpn.monkeybean.ca *.cloudapp.monkeybean.ca *.cloudvpn.monkeybean.ca *.cpcontacts.monkeybean.ca *.desktops1.monkeybean.ca *.email.monkeybean.ca *.exchange.monkeybean.ca *.firewall.monkeybean.ca *.fortiproxy.monkeybean.ca *.fortivpn.monkeybean.ca *.ftp.monkeybean.ca *.gate.monkeybean.ca *.gateway.monkeybean.ca *.globalprotect.monkeybean.ca *.igznbfoq.monkeybean.ca *.imap.monkeybean.ca *.inbound.monkeybean.ca *.jtmfhzteruautodiscover.monkeybean.ca *.mail.monkeybean.ca *.mobileconnect.monkeybean.ca monkeybean.ca *.monkeybean.ca *.office.monkeybean.ca *.owa.monkeybean.ca *.portal.monkeybean.ca *.ra.monkeybean.ca *.rd.monkeybean.ca *.rdweb.monkeybean.ca *.remote.monkeybean.ca *.remoteapp2.monkeybean.ca *.secure.monkeybean.ca *.secureaccess.monkeybean.ca *.smtp.monkeybean.ca *.ssl.monkeybean.ca *.test.monkeybean.ca *.ts.monkeybean.ca *.vdi1.monkeybean.ca *.virtualaccess1.monkeybean.ca *.vpn1.monkeybean.ca *.vpn2.monkeybean.ca *.vpn3.monkeybean.ca *.webdisk.monkeybean.ca *.zteruautodiscover.monkeybean.ca
nutopia.bio *.nutopia.bio *.ww25.nutopia.bio *.ww38.nutopia.bio