CertH certH

doi.org SSL Score & TLS Health Report

Issuer
Google Trust Services
Max TLS
TLS1.2
Cipher
ECDHE-ECDSA-CHACHA20-POLY1305
Expires
12/13/2026( 87 d)
HSTS
✓ Enabled
OCSP Stapling
Disabled

doi.org currently holds an SSL grade of A (95/100) from CertH TLS health monitoring. The site supports TLS1.2, has HSTS enabled, and its certificate is issued by Google Trust Services — certificate validity is unknown. CertH records daily TLS handshake probes into an auditable certificate health trend.

Full certificate & config details

Common Name
doi.org
Key
ec 256bit
Sig Hash
SHA-256
SAN
doi.org · *.doi.org
Fingerprint
e1f738f7cc9e38755223ba6aee41f494b23dd5117c72f17819ff00758eba8206
Indicadores de riesgo
Sin riesgos notables

Tendencia de puntuación

02550751009/10/2026, 3:23:57 AM · 95 (A)9/10/2026, 3:24:08 AM · 95 (A)9/18/2026, 3:23:27 AM · 95 (A)9/18/2026, 3:23:38 AM · 95 (A)

Historial reciente

HoraGrado PuntuaciónEmisor
9/18/2026, 3:23:38 AMA95Google Trust Services
9/18/2026, 3:23:27 AMA95Google Trust Services
9/10/2026, 3:24:08 AMA95Google Trust Services
9/10/2026, 3:23:57 AMA95Google Trust Services

Score change insights · Last 90 days

No score changes recorded yet. Once snapshots accumulate, this section shows why the score moved.

FAQ

Why did my SSL score drop?

Common causes include an expiring certificate, legacy TLS protocols enabled, weak cipher suites negotiated, HSTS removed or server handshake failures. The "Score change insights" section below lists the specific reason for each move.

How often is the score updated?

Watched domains are scanned daily; leaderboard domains get weekly full snapshots. Publicly queried domains append history snapshots under throttling, building an auditable score history.

Does certificate rotation affect the score?

Usually not — normal rotation keeps the score unchanged, unless the new certificate changes key strength, issuing CA or signature algorithm. The insights section flags such events.

How can I improve my SSL score?

Enable TLS 1.3, disable TLS 1.0/1.1, use strong cipher suites (AES-GCM / ChaCha20), deploy HSTS correctly, and keep the certificate valid with sufficient key strength (RSA >= 2048 or ECC >= 256).