Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.jonathanraspiengeas.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 30, 2026
Valid Until
April 30, 2026 79 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DC:1A:FA:AC:BF:8D:3D:10:ED:82:A4:EA:A5:74:36:E4:1A:F9:C4:A1:04:83:3F:5F:C7:3C:E0:00:3F:D6:42:08
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
widget.brij.fi

Other domains in certificate

oongaboonga.api.acadarena.com
www.akcent.space
todo.alexerem.ru
skunkworks.amco.me
andsray.com
admin.momentum.appac.us
admin.appointohealth.com
ar-prints.in
postofficescoin.me-south-1.aws.aurosoftware.net
www.barabana.net
www.batallacultural.org
new.bbparam.com
www.bhallislife.com
auth.camp-stack.com
circlespace.in
m.e2bio.interactivedeveloper.co.kr
www.vprotech.co.th
www.gotech.com.mk
empyrealenergy.com.ng
gorsel.akilliuslu.com.tr
www.huangsoon.com.tw
checkedok.corerfid.net
scoreboard.hirata.dev.br
www.ecoserviceintegral.com.ar
sepa.areandina.edu.co
apply.fairhub.de
dashboard.freshfoodconnect.org
bluemarble.fyne.games
plenoil.gbbapp.com
getdevour.com
glissandco.fr
www.grasertroxler.ch
reservas.guayrestaurante.com.br
www.jellevanlangendonck.be
www.jonathanraspiengeas.com
www.julieshackman.co.uk
www.justfais.al
tmobilemasterclassoffer.kasparovchess.com
alpha.katipolt.com
kdstreeter.net
clinic.test.kevinjacjac.com
keyakinoki.jp
dev-hello-app.kpos.store
www.leguman.ch
mitsuwa.lfv.jp
clothprint.liberte-mode.com
aarnd.livebusinessupdate.com
mahadevagroimpex.in www.mahadevagroimpex.in
google.mailrecipe.com
backend.mein-standort.ch
www.melbite.com
www.mentorific.org
app.musculatus.app
app.myclinic.today
mysynagogue.net
ordemaa.org
www.ouchiacademy.com
www.owensmith.com.au
dev.support.paniscope.app support.paniscope.app
umsjon.pulsmedia.is
share.quirk.money
staging.auth.re-shine.jp
recruiter.recrutae.com.br
staging.app.refractio.fr
www.rhidoctor.co.uk
insights.sealsense.co
securelifesettlement.com
shaperburger.uy
www.shelff.jp
api.silent-james.de
app.singa-long.com
esms.sonice-aioe.com
www.studenttimetable.com
www.sunwesthelicopters.com
taskaid24.com
callscheduler.testive.com
thecompanynyc.com
dev-events.ticketspicket.com
dev.tottup.com
brands.trozo.ai
mfe-load-manager-qa-nocf.truckstop.com
app.trufflemarket.it
auth.useploy.com
vacatable.com
app.vbrnet.com.br
ocrgoogle.vertion1.com test-litigation.vertion1.com
lab4.ic.vezham.com
registration.vida.id
khachhang.vinorder.vn
app.engage.ipra.voyagernetz.us
play.mathmaster.vshyrochuk.com
admin.wanax.com
countdown-zen.wiselywidgets.com
www.wllflve.com
www.xrvisual.com
yakinikufloripa.com.br