Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=telemetry.midaas.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 23, 2025
Valid Until
February 21, 2026
86 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:46:67:92:F7:E4:CE:A1:47:38:6B:28:D0:37:01:AB:7F:31:50:2F:25:53:AD:AF:CD:70:19:D8:6C:DB:5A:72
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
www.playxd.co.uk
mesa.agoramenu.com.br
company.airbuy-japan.com
alphamtcorp.com
alumentica.com
apicheck.dev
www.arashveer.com
archwayapps.com
axintesergiu.xyz
www.batchbase.de
batchbee.de
www.batchbee.de
rpa-dashboarding.bce.technology
bolkansoft.com
www.botprovider.com
bristolpentecostalchurchuk.org
captaincapitalism.store
stage.carrierblue.com
cartfuly.com.mx
cdeeble.com
bot.choroshin.com
cashcounter.cmouse.app
app.cryointelligence.com
www.cryptocostaverage.app
www.darksecret.io
www.digitalnauts.com
domepilates.com
subdomain.doray.ca
myreturns.dpdlocal.co.uk
www.duckhunt.app
auth.ecalendrier.net
www.eden-studio.de
www.edsyntesting.org
www.equestrian.directory
evernest.fi
soknad.fagbrev.io
www.floxi.co
franshiromedia.com
futfb.com
www.galile.io
getdeezel.com
qc.nurture.goama.com
golang-labs.com
haarlemjazz.nl
humanebydesign.com
auth-rc.ikala-c4m.io
inorwa.com
emailsignatures.inventif.dev
www.ipray.online
www.stage-foodcourt.isthara.com
www.keepwords.com
www.komemi.com
www.lisacoppinger.com
www.luisgeraldo.com
development.made.live
blog.makeany.app
mariefitzpatrick.com
studiospace.menuqrate.com
mergeconflict.in
telemetry.midaas.com
dl.midiacode.app
mondocoolstudios.com
ishealth.mor.company
www.mrcyberium.com
mrpbd.org
mtctoner.com
www.mtctoner.com
demo.sintaqu.my.id
nd-filter-expert.de
neeril.com
staging.neuralpayments.com
case.olabbio.com
www.passamezzo.co.uk
www.pcmgroupsrl.it
pebble.world
www.pinningo.com
pixelcode.cl
polalitravels.com
practiceplaygrow.com
quickhomecares.in
www.quickhomecares.in
badtwitter.rglvn.com
fw-versions.rideet.com
ringsumlut.com
cash.rtirl.com
sanaapesa.online
saratogadata.com
www.sewacharitabletrust.org
sistemafiscalmei.com.br
slickbot.io
link.snackhub.eu
sortedbranding.com
stemsearcher.com
demo.stx.world
www.thebeautyofplaces.com
qpbvp.thence.co
links.thereadingcorner.tv
toiletswipe.com
procountor-redirect.vilkas.fi
staging.wecommend.app
Other domains in certificate