77/100 SECURITY SCORE

Certificate Information

Subject
CN=baby.iqbal.my
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 03, 2025
Valid Until
March 03, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
71:C9:B4:95:34:D6:72:68:1F:62:88:11:F0:F7:AE:8F:96:FC:E4:D6:0A:09:40:B7:CC:D9:F8:A8:CE:CA:00:45
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.felixinsurances.com

Other domains in certificate

100xroadmap.app
app-dev.1stcutoutings.com
new-platform-web-dev-fire.51qwe.com
www.abogadoconsultasonline.com
agripanda.it
alkabienesraices.com
jardin.alocquet.eu
itsolutions.amiaengineering.com
antware.mx
ar-remote-assistance.com
assuredgreentech.com
us.production.monday-trees.avisi-apps.com
catboy.bigrat.monster
lounas.bites.fi
bluestacker.com
bm-wass.at
bonanzaafrica.com
brikuleshop.cz
latesttrades.bullsheet.me
www.calculatorwidget.app
calinciupei.com
caroleandcolt.com
www.casadepevale.ro
www.cinenow.ca
www.codeschoolusa.org
decembertreasure.com
designbysphiria.com
lk.digicelgroup.com
digital-dandelion.com
dizveloper.com
www.docinsights.app
www.doggiepaddle.co.uk
www.dr-raymundojuarez.com
www.drjorgeleyvacarditoracico.com
duelotters.com
dukesresidence.com
eclub.space
everyoneonthe.net
evilme.com
facires.com
www.felipematallanap.com
flatmap.be
fortmike.com
franzhoffman.com
geoconnectionsinc.com
grselectromech.com
guitarlessonshull.com
www.guitarlessonsnorwich.com
healthism.com
hiddenhunts.com
idelan.com
idolssalon.com
www.ignatimedia.com
uat.cmacc.in.th
referral.indofintekdg.id
intera-kt.de
baby.iqbal.my
iqsales.cloud
itsgranny.com
www.jennayousef.com
www.joekumoye.com
kkoehler.com
konsa.ai
kulikovaolga.com
www.kuttheline.com
kylejohnston.dev
laurazoee.com
plan.lodzero.com
blueeditor.m1studio.co
michaeldargenio.dev
go.mongz.net
www.muratkaymaz.com
myopic-frog.com
mystoremysign.com
oktoberfestgt.com
www.oneconsultant.ae
prova.opennatur.com
hitbox.paloaltours.org
cred.pedstudioapp.com.br
www.pokercave.no
influencer.pyderin.com
jamon.qryonix.com
www.quasistellar.io
auth.quickaction.app
rootsofpacha.com
www.scorizen.com
seyonserv.com
sgcsolars.in
psms.sksis.ca
smilealittle.co
www.sp-medic.com
www.sueibiandao.io
app.swappyverse.com
freshwaterprioritization.tnc.org
internal.uripgumulya.com
www.villarhouses.com
watkaoluck.com
www.xamaral.com
zone5graphx.com