Open
Cached
·
just now
75/100
SECURITY SCORE
Certificate Information
Subject
CN=www.adm.moub.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 14, 2025
Valid Until
March 14, 2026
77 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FD:DD:27:4D:40:CD:A9:1C:78:EE:92:66:ED:A3:92:C8:61:79:13:C8:16:48:6A:45:8B:A8:DD:4D:FC:1C:EA:CC
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
yanadesigner.com
aagai.site
www.accoprepai.com
q.adesign.work
bhuddhaphysio.aeglepro.in
africultureartcentre.org
stage.link.andelenergi.dk
www.anima.help
apptube.dev
aquahub.hk
render.as-a-service.dev
bandla.app
bazishoon.ir
bombayyachtsailing.com
brfpriser.se
agent.buzztop.io
carinasca.eu
www.snackiyafoodsandbeverages.co.in
codedunn.com
www.ctrl-bee.net
link.digcoach.com
docuvault.co.za
ekihabit.es
entropygrid.net
www.escolasabedoria.com.br
operators.explorenym.net
auth.feastybox.com
oms.fhglobal.es
forgeix.in
generalcontractor.com.mx
zaporizhzhia.mobilitymonitor.habidatum.com
www.handsfreeforweb.com
www.hevoshieroja.info
login.hrz.lol
studio.hrz.lol
teach.dvtien.id.vn
idoz.dev
app2.immigration-check.de
files.jbalazer.com
js.jsglobalconsultants.com
jsglobalconsultants.com
klidnymalybyt.eu
kyleperfume.com
auth.lawslane.com
reg1.lotoclub.io
magicwb.com
manojmanpowersolutions.com
app.martvi.cz
poke-hub.melvernhacktiv8.online
www.meshos.com
meshotex.com
auth.mios.cloud
www.monaai.de
www.adm.moub.com.br
www.lakewood.opendata.report
auth.opentotalk.org
sarva.org.in
paireimpaire.fr
www.paybytheline.com
paydos.tr
pokermunity.com
pratheekbedre.com
www.purahisab.com
www.rbmedilek.cz
gateway.re-marketing.click
www.reacaosolar.com.br
rmanubolu.com
www.rmanubolu.com
rmanubolu.com.au
www.rmanubolu.com.au
rmanubolu.in
roozbehbandpey.de
flames.rorygarand.com
stg.register.krs.satella.shop
su.sdha.jp
get.settle.eu
shriramclinic.com
qa2.shrlinks.com
www.sinki.cc
cloudinsight.speakylink.com
dashboard.spesialis.app
payment.spesialis.app
www.srstores.uk
manager.stampwallet.io
www.subeditorsouth.com
oms.suprol.club
swipeheart.love
www.systemagency.com
tbag.co.za
thegrowthrepo.com
app.tidy.fyi
bwell-clinic.timp.io
tiramarine.com
tnmcqmaster.in
www-static.vleu.net
voicebuild.co
api.whisperschat.app
yogaadya.com
staging.yograde.me
zencoloringdaily.com
Other domains in certificate