Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=app.dvinum.es
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 04, 2025
Valid Until
February 02, 2026
82 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5D:8F:03:50:B4:C5:31:A5:1F:A1:41:59:89:C6:80:BB:F3:75:CD:9E:01:C9:44:E3:58:68:5B:BF:08:27:52:3D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
www.merchandisebot.com
auth.stage.agently.abeja.io
alexandrawedding.com
www.ammantraders.com
www.ancestralfood.com.br
www.ancestralpet.com.br
blog.appaka.ch
aracatubafcsaf.com.br
www.arcangelopisa.com
bg.artboxy.com
exploitant.app.asteriot.fr
hunt-the-thief.astraycorp.com
helpdesk.axsar.com
apascorer.biancostudioapps.com
bimgauge.com
sanmiguelsday.bracelit.es
bulkbeverageco.com
www.admin.buzzmobile.mk
www.canstruct.in
www.canyonmarin.fr
www.carcleaningspecialist.nl
cartiresservice.com
b6-real-estate-dev.carto.solutions
censura.ru
www.chaieb.dev
www.charlesdarwin.com.br
www.charlesdarwinfood.com.br
mail.childrencharitabletrust.org
new.collegehive.in
cramel.jp
crochetia.com
cs-spaceports.net
cabinet.dah-qa.top
dennismeltser.com
dentalben.com.au
app.depatu.com
dfilm.com
www.dharmakumala.com
dmarcer.com
app.drawfi.io
b.driverx.vn
app.dvinum.es
www.dxcleaning.co.uk
diario.elcri.men
energypoint.tech
hugo.eynard-home.fr
app.fan.school
onboarding.finrax.com
flutter-dev.pl
gabilazarini.com.br
app.getveryfast.com
grandmore.com
growstitch.com
www.growstitch.com
pastor.iasdsantamonica.com
www.inatman.com
www.instintoancestral.com.br
1fm9ru37snleoucn.pre-20250316.no.isnot.info
roster-beta.kenoviiva.com
kktilintarkastus.fi
www.lanutrydep.com
lawinfo.com.br
www.letsmeet.space
app.masterthedollar.com
maxmamone.me
mazenhammoud.com
kinderboekenweek.mcdonaldsnederland.app
mingus.dog
dev.mlconnector.com.br
www.motv.world
iecaminosluz.mybookplus.net
receipt.nailsolution.us
norse-com.com
visit.nourishbynara.com
othersverse.com
oussama-kheyar.de
zuhlke.parkalot.io
pendulumart.studio
platic.es
mjfd.portfolioview.co.za
preskosfinance.com
app.publicidadebh.com.br
www.queijodeiaque.com.br
www.queijodeyak.com.br
www.queijodohimalaia.com.br
rozvatech.com
shotbyarya.com
www.sindistrict.net
admin.smartopsve.com
snow4ik.ru
app.spondle.co
spseguro.com.br
life.take-kita.com
www.tcsp-chauffage.fr
mobility-firebase.uplltd.com
waiter-studio.com
wasramit.tn
we-buy-stone-flags.co.uk
techsolve.hafizh.web.id
jott.weekendprojects.xyz
Other domains in certificate