77/100 SECURITY SCORE

Certificate Information

Subject
CN=dashiq.ch
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
March 07, 2026
Valid Until
June 05, 2026 32 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DF:DD:63:9E:C4:56:C4:31:FC:E1:E2:21:B4:E1:EA:6A:75:21:B7:3C:1F:0A:83:22:52:0E:5A:76:AB:80:9F:50
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.geteidolon.app

Other domains in certificate

20mintabletop.com
auth.3cscore.com
dados.aaflabs.com
palace-staging.academytrial.com
alhusnainpetroleumservice.site
www.alkimiaholistica.com
www.anthara.ai
avanpore.com
steve.axtmann.me
www.baselayer.coach
bazogames.com
bet-el-sultan.com
www.bonanza.com.mm
bestellen.buendergrill.de
cloudbasha.com
www.cloudswitch.in
www.colectspot.com.br
comunicak2a.com.br
www.cpak.co.kr
dashiq.ch
au.app.decisionrules.io
deweydentalok.com
fun.dmin.no
www.dominoharbor.com
stage.admin.dresez.com
edenemergencymedicalgroup.com
ekta-m.ektajagrukta.in
www.eldersenterprises.in
www.elecmar.com.au
faridrahim.com
uat-sankul.finncub.com
amritdhara.flutivo.in
www.fsecret.com.br
galloe.it
garigliano.com
app.globalux.de
grayconsulting.group
hagrids.com
haider-alamiri.com
hangrybot.com
mindbridge.holisticai.com
www.invariancequestions.org
iskode.com
japanese47.id.vn
www.knockers.codes
lantakanemas.com
leetrix.com.mx
umc.lempe.com.br
leomine.com
lifescirec.com
www.dev.en.frame.lokalebon.nl
mateus25.pt www.mateus25.pt
maxicompte.matthias-apps.fr
gerencia.monttrading.com
musingsofthemuse.com
www.ntekcomms.com.au
preview.optifit.app
oslojazz.no
www.paudelnabin.com.np
www.phoenixlimited.net
what-number.pizzabunlab.com
business.placepy.com web.placepy.com
atlas.planian.app
pueblosdeensueno.com
www.queensgambitdeclined.com
quickfixremovals.com
test.relay42.dev
www.riverwood-consultancy.eu
www.robingerlach.com
www.robotico.gr
www.safestash.com.br
samjhanapokharel.com.np
web.sangfah.com
testapp.semanticamp.com
test.app.servicecraze.com
sinangunes.tr
www.sofiulyanova.com
www.springair.com.my
beta.tpv.stratya.com
dashboard.tabmate.nl
report.teas.ng
www.techbrowse.in
gameday.thearizonabowl.com
www.tingyilifting.com
www.torokszentmiklosszallas.hu
tpeng.com.br
tqt202416617.id.vn
tucoachempresarial.info
test.tyrata.io
firebase.umemoto1979.com
solar-calculator.valleysunsolarco.com
www.vsindustrial.net
www.waytovivah.com
www.winkkee.fr
tanizawa.wowdesk.jp
yordanangelov.com
app.zmatch.com.br