Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.cloud2mg.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 24, 2025
Valid Until
January 22, 2026
67 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4D:34:16:1D:FB:4A:25:C3:3A:C3:0E:43:92:E8:B8:EB:5C:E8:5D:97:B2:46:FC:3B:26:A3:9D:95:05:79:DB:7C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
www.arcanumarcanorum.com
faq.islam.adiop.com
axie.adrianocola.com
agroform.de
deetrox.aimcomely.com
ezith.aimcomely.com
alexkingconsulting.com
anthonygleason.com
areneda.com
autohuoltotaponen.fi
app.automatoai.com
beankonducta.com
bestofka.cz
www.carromero.cl
celebrityvoice.app
www.cfd-parapente.com
saitoshuka.chance-store.jp
www.changyuwu.me
chicagotopcleaning.com
clipmeweb.app
www.cloud2mg.com
documentos.comprarcasa.com
www.coparenter.pro
crabadakingdom.com
www.cruiseabout.com
www.davidsurprenant.com
www.devspear.com
dezatike.com
www.digitalassetindexfund.com
data.ecmo.app
dev.fareclock.com
farnost-hosteradice.cz
fastsafe-pro.com
figandleaves.com
flowlylink.com
flowsportclub.com
staging.read.forwardchess.com
www.geisel-web.de
site.globalsuq.com
glocalsummit.com
greenlovers.app
www.hireoutstationtaxi.in
hyperpost.co
dripto.innomed.in
www.inoprealty.ae
integrityautohrd.com
www.iowave.in
staging.billing.ipregistry.co
jainaiyush.ca
jawedsway.com
jenniferzardus.com
jobyo.io
joshuaforvermont.com
kanro.ca
krumiew.clinic
www.kursatufukcoskun.com
nandha.kuruvi.club
www.lapatatechaude.ca
www.leftenant.app
lifebits.app
logoapps.com.br
firebase.lotusvision.vn
www.lucianolagassa.com.ar
www.m-rental.co
www.maistorai.page
marmarissogut.net
mdsmeducation.com
michael-orenda.com
dev-pro-v1.milva.dk
moowstudios.com
admin.museli.app
www.pu-business.myreshn.com
nbdigi.com
link.omena.app
www.oxeye.ai
auth.planmo.com
play.primetimemath.com
www.rashchupkin.com
rishabhrahul.com
admin.santlopon.com
go.shinnova.io
sightreading.app
www.sistemainterno.com.br
www.sjnarmstrong.com
app.squadx.online
sp-partner.steadypay.co
euna.stl.dev
www.suddenbooks.com
symteq.io
szabat.be
www.telebot.top
www.timessquareinc.com
www.tinttech.ch
www.traditionequipmentleasing.com
www.unbadpaste.com
universalcart.online
web.vastraapp.com
vndynapp.com
app.wealthenv.com
www.weight-training.app
Other domains in certificate