77/100 SECURITY SCORE

Certificate Information

Subject
CN=recording-qa.goodkind.tv
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 27, 2025
Valid Until
February 25, 2026 82 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7E:34:F1:CF:14:0F:E3:89:05:0D:7E:E8:E3:6C:FB:47:AE:BE:26:1E:1B:17:DC:63:54:84:A3:C0:3D:CA:C9:CF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.legalfactory.in

Other domains in certificate

36m.uk
img.app.adiop.com
staging.alinkeo.com
admin.amebyana.com
ktp.web.appliedautonomy.no
mobile-tasktrack.appsolutions.top
arpithaexports.com
www.atlantisbeachvilla.gr
kb.avada.net
www.beardsandfur.com
learners.bethebest.ai
boulazacbasketdordogne.deeplinks.bfansports.com fcchambly.deeplinks.bfansports.com genoacfc.deeplinks.bfansports.com gothiques.deeplinks.bfansports.com grenoblefoot38.deeplinks.bfansports.com heitecvolleys.deeplinks.bfansports.com
beta-admin.bidmii.com
boutique-marketing-agency.co.uk
canopyintelligence.co.uk
santa.cayden.xyz
parkeasy.chetvertkov.me
www.chitchatsource.com
padelseinajoki.cintoia.com
dev.account.clac.io partner.clac.io
outcomes.clinicspeak.com
agent.shubhmoney.co.in
mokoko.co.kr
www.makebetter.com.jm
www.cookie.world
www.create-a-tournament.com
daheimladen.com
dataslots.org
daze.tokyo
diewithme.online
dikshitpatoliya.com
center.dnlogis.vn
aop.early.vision
edxn.tv
www.electricfish.xyz
www.erioon.com
hrcore.event.rocks
fairheadkenya.com
fivefamilyactivities.com
fluttercommunityibague.co
fsm.forthe.top
recording-qa.goodkind.tv
crm-elephant.gridcockpit.com
www.happ-e-tax.co.za
www.harshitsharma.in
www.helloworldapp.net
www.housekeyrealty.in
www.isatrainblocking11th.com
ismattworking.com
jamazing.band
www.janeschmidt.dk
www.jotik.app
www.journal-freiburg.de
admin.kanzaeg.com
kentkad.im
kenzsoft.com
letter.kingbillycasino.com
kuuk.la
beta.leedus.io
trivia-dev.da.letsdive.io trivia-prod.da.letsdive.io
www.mahkotabumi.id
company.mandal.one
maridalsveien160.no
testgo.mebba.ru
merliniumiot.com
ijmland-ballot.mhub.my
misterpushup.com
www.modality.co.nz
mtfridgerepair.com
www.nautiquiz.net
www.neuraccel.de
www.ollivere.co
stage-app.onpointify.com
ops-staging.picker.work
psciai.com
docs.purrfecttool.com
q.quex.me
shopping.rsshah.net
www.scavenger.social
scorebug.online
app.souqtajer.com
support.test.tellow.nl
expert-preprod.tiime.fr
top500fails.com
tristanscakesandbakes.co.uk
www.trustedfinancial.org
www.twkdev.cc
www.tzmartin.com
www.unifiedmind.org
staging.walpoleoutdoors.com
beta.flow.waylar.net
www.westminsterrecoverycenter.net